CVE-2020-17353: Critical severity lilypond vulnerability
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-17353?
CVE-2020-17353 has a medium severity rating due to its potential to allow execution of dangerous PostScript code.
How do I fix CVE-2020-17353?
To remediate CVE-2020-17353, it is recommended to upgrade LilyPond to versions 2.21.5 or higher.
Which versions of LilyPond are affected by CVE-2020-17353?
CVE-2020-17353 affects LilyPond versions up to 2.20.0 and 2.21.0 through 2.21.4.
What type of vulnerability is CVE-2020-17353 classified as?
CVE-2020-17353 is classified as a code execution vulnerability due to insufficient restrictions on embedded PostScript and SVG.
In which systems can CVE-2020-17353 be found?
CVE-2020-17353 can be found in various operating systems including Debian, Fedora, and OpenSUSE that use the affected versions of LilyPond.