Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7hmv-6p8v-7rmw

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.

gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.

EPSS

Процентиль: 93%
0.11035
Средний

7.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.

CVSS3: 7.8
nvd
почти 8 лет назад

gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.

CVSS3: 7.8
debian
почти 8 лет назад

gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on i ...

EPSS

Процентиль: 93%
0.11035
Средний

7.8 High

CVSS3

Дефекты

CWE-502