ALAS-2015-630

Related Vulnerabilities: CVE-2015-8557  

An unsafe use of string concatenation in a shell string occurs in FontManager. If the developer allows the attacker to choose the font and outputs an image, the attacker can execute any shell command on the remote system. The name variable injected comes from the constructor of FontManager, which is invoked by ImageFormatter from options.

ALAS-2015-630


Amazon Linux AMI Security Advisory: ALAS-2015-630
Advisory Release Date: 2015-12-14 15:14 Pacific
Advisory Updated Date: 2015-12-14 15:14 Pacific
Severity: Important
References: CVE-2015-8557 

Issue Overview:

An unsafe use of string concatenation in a shell string occurs in FontManager. If the developer allows the attacker to choose the font and outputs an image, the attacker can execute any shell command on the remote system. The name variable injected comes from the constructor of FontManager, which is invoked by ImageFormatter from options.


Affected Packages:

python-pygments


Issue Correction:
Run yum update python-pygments to update your system.

New Packages:
noarch:
    python26-pygments-1.4-4.12.amzn1.noarch
    python27-pygments-1.4-4.12.amzn1.noarch

src:
    python-pygments-1.4-4.12.amzn1.src