First published: Fri Feb 23 2018(Updated: )
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Leptonica | =1.74.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18196 is classified as a medium severity vulnerability.
To fix CVE-2017-18196, upgrade Leptonica to version 1.74.5 or later.
CVE-2017-18196 is a path traversal vulnerability that can allow local users to bypass file restrictions.
CVE-2017-18196 affects Leptonica version 1.74.4.
CVE-2017-18196 is not a remote exploit; it requires local access to the affected system.