First published: Wed Aug 05 2020(Updated: )
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/lilypond | 2.19.81+really-2.18.2-13+deb10u1 2.22.0-10 2.24.1-2 | |
Lilypond Lilypond | <=2.20.0 | |
Lilypond Lilypond | >=2.21.0<=2.21.4 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
Debian Debian Linux | =10.0 | |
openSUSE Backports SLE | =15.0-sp2 | |
openSUSE Leap | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.