First published: Wed Aug 05 2020(Updated: )
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/lilypond | 2.19.81+really-2.18.2-13+deb10u1 2.22.0-10 2.24.1-2 | |
LilyPond | <=2.20.0 | |
LilyPond | >=2.21.0<=2.21.4 | |
Red Hat Fedora | =31 | |
Red Hat Fedora | =32 | |
Debian Linux | =10.0 | |
openSUSE Backports | =15.0-sp2 | |
SUSE Linux | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17353 has a medium severity rating due to its potential to allow execution of dangerous PostScript code.
To remediate CVE-2020-17353, it is recommended to upgrade LilyPond to versions 2.21.5 or higher.
CVE-2020-17353 affects LilyPond versions up to 2.20.0 and 2.21.0 through 2.21.4.
CVE-2020-17353 is classified as a code execution vulnerability due to insufficient restrictions on embedded PostScript and SVG.
CVE-2020-17353 can be found in various operating systems including Debian, Fedora, and OpenSUSE that use the affected versions of LilyPond.