CVE-2017-18196
published 2018-02-23CVE-2017-18196: Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow…
PriorityP410low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.42%
34.4th percentile
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | leptonlib | < leptonlib 1.74.4-2 (bookworm) | leptonlib 1.74.4-2 (bookworm) |
| leptonica | leptonica | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m7cf-9jqx-8xrq: Leptonica 1
ghsa_unreviewed·2022-05-13
CVE-2017-18196 [LOW] CWE-22 GHSA-m7cf-9jqx-8xrq: Leptonica 1
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.
OSV
leptonlib vulnerabilities
osv·2021-03-15·CVSS 3.3
CVE-2017-18196 [LOW] leptonlib vulnerabilities
leptonlib vulnerabilities
It was discovered that Leptonica incorrectly handled path names. An
attacker could possibly use this issue to obtain sensitive information.
This issue only affected Ubuntu 16.04 ESM. (CVE-2017-18196)
It was discovered that Leptonica incorrectly handled certain input
arguments. An attacker could possibly use this issue to execute arbitrary
commands. (CVE-2018-3836)
It was discovered that Leptonica incorrectly handled input arguments. An
attacker could possibly use this issue to cause a denial of service or
other unspecified impact. (CVE-2018-7186)
OSV
CVE-2017-18196: Leptonica 1
osv·2018-02-23·CVSS 3.3
CVE-2017-18196 [LOW] CVE-2017-18196: Leptonica 1
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.
Ubuntu
Leptonica vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 3.3
CVE-2018-7186 [LOW] Leptonica vulnerabilities
Title: Leptonica vulnerabilities
Summary: Several security issues were fixed in Leptonica.
It was discovered that Leptonica incorrectly handled path names. An
attacker could possibly use this issue to obtain sensitive information.
This issue only affected Ubuntu 16.04 ESM. (CVE-2017-18196)
It was discovered that Leptonica incorrectly handled certain input
arguments. An attacker could possibly use this issue to execute arbitrary
commands. (CVE-2018-3836)
It was discovered that Leptonica incorrectly handled input arguments. An
attacker could possibly use this issue to cause a denial of service or
other unspecified impact. (CVE-2018-7186)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2017-18196: leptonlib - Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path com...
vendor_debian·2017·CVSS 3.3
CVE-2017-18196 [LOW] CVE-2017-18196: leptonlib - Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path com...
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.
Scope: local
bookworm: resolved (fixed in 1.74.4-2)
bullseye: resolved (fixed in 1.74.4-2)
forky: resolved (fixed in 1.74.4-2)
sid: resolved (fixed in 1.74.4-2)
trixie: resolved (fixed in 1.74.4-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-18196 leptonica: Mishandled pathnames in /tmp subdirectories can allow users to bypass intended file restrictions [epel-all]
bugzilla·2018-02-27·CVSS 3.3
CVE-2017-18196 [LOW] CVE-2017-18196 leptonica: Mishandled pathnames in /tmp subdirectories can allow users to bypass intended file restrictions [epel-all]
CVE-2017-18196 leptonica: Mishandled pathnames in /tmp subdirectories can allow users to bypass intended file restrictions [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2017-18196 leptonica: Mishandled pathnames in /tmp subdirectories can allow users to bypass intended file restrictions [fedora-all]
bugzilla·2018-02-27·CVSS 3.3
CVE-2017-18196 [LOW] CVE-2017-18196 leptonica: Mishandled pathnames in /tmp subdirectories can allow users to bypass intended file restrictions [fedora-all]
CVE-2017-18196 leptonica: Mishandled pathnames in /tmp subdirectories can allow users to bypass intended file restrictions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mess
Bugzilla
CVE-2017-18196 leptonica: Mishandled pathnames in /tmp subdirectories can allow users to bypass intended file restrictions
bugzilla·2018-02-27·CVSS 3.3
CVE-2017-18196 [LOW] CVE-2017-18196 leptonica: Mishandled pathnames in /tmp subdirectories can allow users to bypass intended file restrictions
CVE-2017-18196 leptonica: Mishandled pathnames in /tmp subdirectories can allow users to bypass intended file restrictions
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree.
Additional References:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=885704
Discussion:
Created leptonica tracking bugs for this issue:
Affects: epel-all [bug 1549412]
Affects: fedora-all [bug 1549411]
2018-02-23
Published