CVE-2018-7440OS Command Injection in Leptonica

Severity
9.8CRITICALNVD
OSV7.8
EPSS
1.8%
top 17.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 23
Latest updateMay 13

Description

An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot rootname argument. This issue exists because of an incomplete fix for CVE-2018-3836.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

debiandebian/leptonlib< leptonlib 1.75.3-3 (bookworm)

Also affects: Debian Linux 7.0

🔴Vulnerability Details

2
GHSA
GHSA-x83x-c4xw-rr5g: An issue was discovered in Leptonica through 12022-05-13
OSV
CVE-2018-7440: An issue was discovered in Leptonica through 12018-02-23

📋Vendor Advisories

1
Debian
CVE-2018-7440: leptonlib - An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput functio...2018

💬Community

4
Bugzilla
CVE-2018-7440 leptonica: gplotMakeOutput command injection (CVE-2018-3836 incomplete fix)2018-02-27
Bugzilla
CVE-2018-7440 leptonica: gplotMakeOutput command injection (CVE-2018-3836 incomplete fix) [epel-all]2018-02-27
Bugzilla
CVE-2018-7440 mingw-leptonica: leptonica: gplotMakeOutput command injection (CVE-2018-3836 incomplete fix) [fedora-all]2018-02-27
Bugzilla
CVE-2018-7440 leptonica: gplotMakeOutput command injection (CVE-2018-3836 incomplete fix) [fedora-all]2018-02-27