Security restrictions bypass in LilyPond - CVE-2020-17353
Published: August 31, 2020
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to application does not properly impose security restrictions on on embedded-ps and embedded-svg, when -dsafe is used. A remote attacker can create a specially crafted PostScript file, pass it to the affected application, bypass imposed security restrictions and execute arbitrary code on the target system.
Affected software
lilypond (Debian package)
lilypond
SUSE Linux
Opensuse
Fedora
How to mitigate CVE-2020-17353
lilypond (Debian package) - update to 2.19.81+really-2.18.2-13+deb10u1
lilypond - addressed in versions 2.19.84-3.fc31, 2.19.84-3.fc32
External References
- http://git.savannah.gnu.org/gitweb/?p=lilypond.git;a=commit;h=b84ea4740f3279516905c5db05f4074e777c16ff
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QG2JUV4UTIA27JUE6IZLCEFP5PYSFPF4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W2JYMVLTPSNYS5F7TBHKIXUZZJIJAMRX/
- https://www.debian.org/security/2020/dsa-4756