Description
An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary code execution. An attacker can provide a malicious path as input to an application that passes attacker data to this function to trigger this vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1284-1 | leptonlib security update |
Debian DLA |
DLA-1302-1 | leptonlib security update |
EUVD |
EUVD-2018-15622 | An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary code execution. An attacker can provide a malicious path as input to an application that passes attacker data to this function to trigger this vulnerability. |
Ubuntu USN |
USN-4819-1 | Leptonica vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-09-16T16:22:40.419Z
Reserved: 2018-01-02T00:00:00.000Z
Link: CVE-2018-3836
No data.
Status : Modified
Published: 2018-04-24T19:29:03.970
Modified: 2024-11-21T04:06:08.340
Link: CVE-2018-3836
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN