CVE-2018-7440: OS Command Injection
An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot rootname argument. This issue exists because of an incomplete fix for CVE-2018-3836.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7440?
CVE-2018-7440 is considered a critical vulnerability due to its potential for command injection.
How do I fix CVE-2018-7440?
To fix CVE-2018-7440, update Leptonica to a version higher than 1.75.3 or apply any security patches provided by your operating system.
What are the main vulnerabilities associated with CVE-2018-7440?
CVE-2018-7440 allows command injection through the gplotMakeOutput function, primarily via the gplot rootname argument.
Which versions of Leptonica are affected by CVE-2018-7440?
All versions of Leptonica up to and including 1.75.3 are affected by CVE-2018-7440.
What does CVE-2018-7440 mean for users of Debian 7.0?
Users of Debian 7.0 should be aware that they are vulnerable to CVE-2018-7440 and should take steps to secure their systems.