9.1
CVSSv3

CVE-2018-7442

Published: 23/02/2018 Updated: 18/12/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

An issue exists in Leptonica up to and including 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversal and arbitrary file overwrite.

Vulnerable Product Search on Vulmon Subscribe to Product

leptonica leptonica

Vendor Advisories

Debian Bug report logs - #898439 leptonlib: CVE-2018-7442 Package: src:leptonlib; Maintainer for src:leptonlib is Jeff Breidenbach <jab@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 11 May 2018 17:21:01 UTC Severity: important Tags: security, upstream Found in version leptonlib/1753 ...