Security restrictions bypass in LilyPond - CVE-2020-17353

 

Security restrictions bypass in LilyPond - CVE-2020-17353

Published: August 31, 2020


Vulnerability identifier: #VU46148
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-17353
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to application does not properly impose security restrictions on on embedded-ps and embedded-svg, when  -dsafe is used. A remote attacker can create a specially crafted PostScript file, pass it to the affected application, bypass imposed security restrictions and execute arbitrary code on the target system.


Affected software

LilyPond
lilypond (Debian package)
lilypond
SUSE Linux
Opensuse
Fedora

How to mitigate CVE-2020-17353

Install updates from vendor's website.

LilyPond - update to 2.21.5
lilypond (Debian package) - update to 2.19.81+really-2.18.2-13+deb10u1
lilypond - addressed in versions 2.19.84-3.fc31, 2.19.84-3.fc32

External References

Related Security Bulletins