SB2018012207 - Arbitrary code execution in Leptonica
Published: January 22, 2018
Security Bulletin ID
SB2018012207
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Command injection (CVE-ID: CVE-2018-3836)
The vulnerability allows a remote attacker to inject arbitrary commands.The weakness exists in the gplotMakeOutput function due to insufficient validation of user-supplied input. A local attacker can submit a specially crafted gplot rootname argument, inject arbitrary commands and execute arbitrary code with system or root privileges.
Successful exploitation of the vulnerabiiity may result in system compromise.
Remediation
Install update from vendor's website.