vulnerability

SUSE: CVE-2020-17353: SUSE Linux Security Advisory

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Aug 5, 2020
Added
Sep 20, 2020
Modified
Oct 22, 2021

Description

scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.

Solution(s)

suse-upgrade-lilypondsuse-upgrade-lilypond-docsuse-upgrade-lilypond-doc-cssuse-upgrade-lilypond-doc-desuse-upgrade-lilypond-doc-essuse-upgrade-lilypond-doc-frsuse-upgrade-lilypond-doc-hususe-upgrade-lilypond-doc-itsuse-upgrade-lilypond-doc-jasuse-upgrade-lilypond-doc-nlsuse-upgrade-lilypond-doc-zhsuse-upgrade-lilypond-emmentaler-fontssuse-upgrade-lilypond-fonts-commonsuse-upgrade-lilypond-texgy-fonts
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.