LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scope, as demonstrated by dangerous Scheme code in a .ly file that causes arbitrary code execution during conversion to a different file format. NOTE: in 2.24 and later versions, safe mode is removed, and the product no longer tries to block code execution when external files are used.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade lilypond | Jul 30, 2024 | Apr 15, 2023 |
| Suse | — | Upgrade lilypondUpgrade lilypond-emmentaler-fontsUpgrade lilypond-fonts-commonUpgrade libguile1-develUpgrade guile1-modules-2_2Upgrade lilypond-doc-nlUpgrade lilypond-doc-itUpgrade lilypond-doc-csUpgrade lilypond-doc-frUpgrade lilypond-doc-jaUpgrade lilypond-doc-huUpgrade lilypond-docUpgrade guile1Upgrade lilypond-doc-deUpgrade lilypond-doc-zhUpgrade lilypond-doc-esUpgrade libguile-2_2-1 | Aug 9, 2024 | Apr 15, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub