9.8
CVSSv3

CVE-2020-17353

Published: 05/08/2020 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

scm/define-stencil-commands.scm in LilyPond up to and including 2.20.0, and 2.21.x up to and including 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lilypond lilypond

fedoraproject fedora 31

fedoraproject fedora 32

debian debian linux 10.0

opensuse leap 15.2

opensuse backports sle 15.0

Vendor Advisories

Debian Bug report logs - #968993 lilypond: CVE-2020-17353 Package: src:lilypond; Maintainer for src:lilypond is Don Armstrong <don@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 25 Aug 2020 14:00:04 UTC Severity: grave Tags: security, upstream Found in versions lilypond/2200-1, lilyp ...
Faidon Liambotis discovered that Lilypond, a program for typesetting sheet music, did not restrict the inclusion of Postscript and SVG commands when operating in safe mode, which could result in the execution of arbitrary code when rendering a typesheet file with embedded Postscript code For the stable distribution (buster), this problem has been ...

Github Repositories

Writeup for 2nd PKU GeekGame

2nd PKU GeekGame Writeup wwx 2022-11-27 Misc †签到† 解法同第一届签到题。从 PDF 文件中复制文字,得到 fa{ecm_oPUGeGmV! lgWloet_K_ekae2} 从上往下、从左往右读,获得 flag{Welcome_to_PKU_GeekGameV2!}。 小北问答 · 极速版 第 1 题:支持 WebP 图片格式的最早 Firefox 版本