Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8557

Опубликовано: 28 сент. 2015
Источник: redhat
CVSS2: 5.1

Описание

The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.2python-pygmentsWill not fix
Red Hat Enterprise Linux 6python-pygmentsWill not fix
Red Hat Enterprise Linux 7python-pygmentsWill not fix
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)python-pygmentsWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-pygmentsWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)python-pygmentsWill not fix
Red Hat Software Collectionspython27-python-pygmentsWill not fix
Red Hat Software Collectionspython33-python-pygmentsWill not fix
Red Hat Software Collectionsrh-python34-python-pygmentsWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1276321python-pygments: Shell injection in FontManager._get_nix_font_path

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 9
ubuntu
около 10 лет назад

The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.

CVSS3: 9
nvd
около 10 лет назад

The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.

CVSS3: 9
debian
около 10 лет назад

The FontManager._get_nix_font_path function in formatters/img.py in Py ...

CVSS3: 9
github
больше 3 лет назад

Command Injection in Pygments

5.1 Medium

CVSS2