CVE-2020-17353
published 2020-08-05CVE-2020-17353: scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.37%
81.9th percentile
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | lilypond | < lilypond 2.20.0-2 (bookworm) | lilypond 2.20.0-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| lilypond | lilypond | <= 2.20.0 | — |
| lilypond | lilypond | >= 0 < 2.20.0-2 | 2.20.0-2 |
| lilypond | lilypond | >= 0 < 2.20.0-2 | 2.20.0-2 |
| lilypond | lilypond | >= 0 < 2.20.0-2 | 2.20.0-2 |
| lilypond | lilypond | >= 0 < 2.20.0-2 | 2.20.0-2 |
| lilypond | lilypond | 2.21.0 – 2.21.4 | — |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wg4f-3xq5-x79h: scm/define-stencil-commands
ghsa_unreviewed·2022-05-24
CVE-2020-17353 [HIGH] GHSA-wg4f-3xq5-x79h: scm/define-stencil-commands
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
OSV
CVE-2020-17353: scm/define-stencil-commands
osv·2020-08-05·CVSS 9.8
CVE-2020-17353 [CRITICAL] CVE-2020-17353: scm/define-stencil-commands
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
Debian
CVE-2020-17353: lilypond - scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2...
vendor_debian·2020·CVSS 9.8
CVE-2020-17353 [CRITICAL] CVE-2020-17353: lilypond - scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2...
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
Scope: local
bookworm: resolved (fixed in 2.20.0-2)
bullseye: resolved (fixed in 2.20.0-2)
forky: resolved (fixed in 2.20.0-2)
sid: resolved (fixed in 2.20.0-2)
trixie: resolved (fixed in 2.20.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-17353 lilypond: lacks of restrictions on embedded-ps and embedded-svg when -dsafe is used [fedora-all]
bugzilla·2020-08-05·CVSS 9.8
CVE-2020-17353 [CRITICAL] CVE-2020-17353 lilypond: lacks of restrictions on embedded-ps and embedded-svg when -dsafe is used [fedora-all]
CVE-2020-17353 lilypond: lacks of restrictions on embedded-ps and embedded-svg when -dsafe is used [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2020-17353 lilypond: lacks of restrictions on embedded-ps and embedded-svg when -dsafe is used
bugzilla·2020-08-05·CVSS 9.8
CVE-2020-17353 [CRITICAL] CVE-2020-17353 lilypond: lacks of restrictions on embedded-ps and embedded-svg when -dsafe is used
CVE-2020-17353 lilypond: lacks of restrictions on embedded-ps and embedded-svg when -dsafe is used
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
Reference and upstream commit:
http://git.savannah.gnu.org/gitweb/?p=lilypond.git;a=commit;h=b84ea4740f3279516905c5db05f4074e777c16ff
Discussion:
Created lilypond tracking bugs for this issue:
Affects: fedora-all [bug 1866489]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
http://git.savannah.gnu.org/gitweb/?p=lilypond.git%3Ba=commit%3Bh=b84ea4740f3279516905c5db05f4074e777c16ffhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00076.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QG2JUV4UTIA27JUE6IZLCEFP5PYSFPF4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W2JYMVLTPSNYS5F7TBHKIXUZZJIJAMRX/https://www.debian.org/security/2020/dsa-4756http://git.savannah.gnu.org/gitweb/?p=lilypond.git%3Ba=commit%3Bh=b84ea4740f3279516905c5db05f4074e777c16ffhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00076.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QG2JUV4UTIA27JUE6IZLCEFP5PYSFPF4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W2JYMVLTPSNYS5F7TBHKIXUZZJIJAMRX/https://www.debian.org/security/2020/dsa-4756
2020-08-05
Published