5.1
CVSSv2

CVE-2019-12761

Published: 06/06/2019 Updated: 03/08/2021
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

A code injection issue exists in PyXDG prior to 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_CONFIG_DIRS must be set up to trigger xdg.Menu.parse parsing within the directory containing this file. This is due to a lack of sanitization in xdg/Menu.py before an eval call.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python pyxdg

Vendor Advisories

Debian Bug report logs - #930099 pyxdg: CVE-2019-12761 Package: src:pyxdg; Maintainer for src:pyxdg is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 6 Jun 2019 21:21:02 UTC Severity: normal Tags: security, upstream Found in ...
Impact: Moderate Public Date: 2019-06-01 CWE: CWE-94 Bugzilla: 1718204: CVE-2019-12761 pyxdg: code inje ...