Remote code execution in LilyPond



Published: 2020-08-31
Risk High
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2020-17353
CWE-ID CWE-264
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
LilyPond
Universal components / Libraries / Scripting languages

Vendor LilyPond

Security Bulletin

This security bulletin contains one high risk vulnerability.

1) Security restrictions bypass

EUVDB-ID: #VU46148

Risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-17353

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to application does not properly impose security restrictions on on embedded-ps and embedded-svg, when  -dsafe is used. A remote attacker can create a specially crafted PostScript file, pass it to the affected application, bypass imposed security restrictions and execute arbitrary code on the target system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

LilyPond: 2.10.1 - 2.21.4

External links

http://git.savannah.gnu.org/gitweb/?p=lilypond.git;a=commit;h=b84ea4740f3279516905c5db05f4074e777c16ff
http://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QG2JUV4UTIA27JUE6IZLCEFP5PYSFPF4/
http://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W2JYMVLTPSNYS5F7TBHKIXUZZJIJAMRX/
http://www.debian.org/security/2020/dsa-4756


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###