CVE-2017-18196: Path Traversal
Published Feb 23, 2018
·Updated
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.
Affected Software
1 affected component
Leptonica Leptonica=1.74.4
Event History
Feb 23, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18196?
CVE-2017-18196 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-18196?
To fix CVE-2017-18196, upgrade Leptonica to version 1.74.5 or later.
3
What type of vulnerability is CVE-2017-18196?
CVE-2017-18196 is a path traversal vulnerability that can allow local users to bypass file restrictions.
4
Which software versions are affected by CVE-2017-18196?
CVE-2017-18196 affects Leptonica version 1.74.4.
5
Can CVE-2017-18196 be exploited remotely?
CVE-2017-18196 is not a remote exploit; it requires local access to the affected system.