CVE-2019-12172: Path Traversal
Published May 17, 2019
·Updated
Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demonstrated by file:\\\ on macOS or Linux, or file://C| on Windows. This is different from CVE-2019-12137.
Affected Software
4 affected components
Typora Typora=0.9.9.21.1
Apple iOS and macOS
Linux Linux kernel
Microsoft Windows
Event History
May 17, 2019
CVE Published
via MITRE·10:30 PM
Data Sourced
via MITRE·10:30 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12172?
The severity of CVE-2019-12172 is rated as high (7.8).
2
How does CVE-2019-12172 allow arbitrary code execution?
CVE-2019-12172 allows arbitrary code execution by exploiting a modified file: URL syntax in the HREF attribute of an AREA element.
3
Which version of Typora is affected by CVE-2019-12172?
Typora version 0.9.9.21.1 is affected by CVE-2019-12172.
4
Is Apple Mac OS X affected by CVE-2019-12172?
No, Apple Mac OS X is not affected by CVE-2019-12172.
5
Are Linux and Microsoft Windows vulnerable to CVE-2019-12172?
No, Linux and Microsoft Windows are not vulnerable to CVE-2019-12172.