Описание
GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| ocrfeeder | fixed | 0.8.5-1 | package | |
| ocrfeeder | no-dsa | bullseye | package | |
| ocrfeeder | no-dsa | buster | package | |
| ocrfeeder | no-dsa | stretch | package |
Примечания
https://gitlab.gnome.org/GNOME/ocrfeeder/-/merge_requests/13
https://gitlab.gnome.org/GNOME/ocrfeeder/-/commit/9209bce8afaf6fde19cdac7f5eaea1b744c3e79e (0.8.5)
https://gitlab.gnome.org/GNOME/ocrfeeder/-/commit/afea0e722f1d14eaf14bf0e5ebb444d3271ff1ef (0.8.5)
Связанные уязвимости
CVSS3: 9.8
ubuntu
почти 4 года назад
GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.
CVSS3: 9.8
nvd
почти 4 года назад
GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.
CVSS3: 9.8
github
почти 4 года назад
GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.