Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-7442

Опубликовано: 23 фев. 2018
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversal and arbitrary file overwrite.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
leptonlibfixed1.76.0-1package
leptonlibignoredwheezypackage

Примечания

  • https://lists.debian.org/debian-lts/2018/02/msg00086.html

  • https://github.com/DanBloomberg/leptonica/commit/24cca39cbeafd7943fb6ec723c9c1f525c24eb9f

  • The patch deactivates debugging functions by default and thus changes behaviour.

EPSS

Процентиль: 42%
0.00204
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
почти 8 лет назад

An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversal and arbitrary file overwrite.

CVSS3: 9.1
nvd
почти 8 лет назад

An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversal and arbitrary file overwrite.

CVSS3: 9.1
github
больше 3 лет назад

An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversal and arbitrary file overwrite.

EPSS

Процентиль: 42%
0.00204
Низкий