Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1022717
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Newsgroups | linux.debian.bugs.dist |
| Subject | Bug#968993: lilypond: CVE-2020-17353 |
| Date | 2020-08-25 16:10 +0200 |
| Message-ID | <AHHO9-Rl-3@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
Source: lilypond
Version: 2.20.0-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>
Control: found -1 2.19.81+really-2.18.2-13
Hi,
The following vulnerability was published for lilypond.
CVE-2020-17353[0]:
| scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x
| through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps
| and embedded-svg, as demonstrated by including dangerous PostScript
| code.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2020-17353
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17353
[1] http://git.savannah.gnu.org/gitweb/?p=lilypond.git;a=commit;h=b84ea4740f3279516905c5db05f4074e777c16ff
Regards,
Salvatore
Back to linux.debian.bugs.dist | Previous | Next | Find similar | Unroll thread
Bug#968993: lilypond: CVE-2020-17353 Salvatore Bonaccorso <carnil@debian.org> - 2020-08-25 16:10 +0200
csiph-web