5
CVSSv2

CVE-2019-17400

Published: 21/10/2019 Updated: 23/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The unoconv package prior to 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

universal office converter project universal office converter

Vendor Advisories

Synopsis Moderate: unoconv security update Type/Severity Security Advisory: Moderate Topic An update for unoconv is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, wh ...
Debian Bug report logs - #943561 unoconv: CVE-2019-17400 Package: src:unoconv; Maintainer for src:unoconv is Vincent Bernat <bernat@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 26 Oct 2019 14:39:01 UTC Severity: grave Tags: security, upstream Found in version unoconv/07-11 Fixed in ...