First published: Fri Feb 23 2018(Updated: )
An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversal and arbitrary file overwrite.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Leptonica | <=1.75.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7442 is classified as a moderate severity vulnerability due to its potential for path traversal and arbitrary file overwrite.
To fix CVE-2018-7442, upgrade Leptonica to version 1.75.4 or later, where the vulnerability is addressed.
CVE-2018-7442 can be exploited via specially crafted inputs that include '/' characters in the gplot rootname argument.
CVE-2018-7442 affects Leptonica versions up to and including 1.75.3.
CVE-2018-7442 is primarily a local vulnerability as it requires an attacker to have access to the software inputs to exploit the flaw.