UBUNTU-CVE-2018-10992
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-10992
Summary:
Details: lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --proxy-pac-file argument, because the GNU Guile code uses the system Scheme procedure instead of the system* Scheme procedure. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-17523.
References: https://ubuntu.com/security/CVE-2018-10992, https://bugs.debian.org/898373, https://www.cve.org/CVERecord?id=CVE-2018-10992
Affected packages
Package
Name: lilypond
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
