[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-8557Date: (C)2016-02-11   (M)2023-12-22


The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 9.0CVSS Score : 9.3
Exploit Score: 2.2Exploit Score: 8.6
Impact Score: 6.0Impact Score: 10.0
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: COMPLETE
Scope: CHANGEDIntegrity: COMPLETE
Confidentiality: HIGHAvailability: COMPLETE
Integrity: HIGH 
Availability: HIGH 
  
Reference:
http://seclists.org/fulldisclosure/2015/Oct/4
DSA-3445
GLSA-201612-05
USN-2862-1
http://www.openwall.com/lists/oss-security/2015/12/14/6
http://www.openwall.com/lists/oss-security/2015/12/14/17
http://packetstormsecurity.com/files/133823/Pygments-FontManager._get_nix_font_path-Shell-Injection.html
http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
https://bitbucket.org/birkenfeld/pygments-main/pull-requests/501/fix-shell-injection-in/diff

CPE    14
cpe:/a:pygments:pygments:2.0:rc1
cpe:/a:pygments:pygments:2.0
cpe:/a:pygments:pygments:1.2.2
cpe:/a:pygments:pygments:1.3.1
...
CWE    1
CWE-78
OVAL    4
oval:org.secpod.oval:def:52665
oval:org.secpod.oval:def:1200181
oval:org.secpod.oval:def:602332
oval:org.secpod.oval:def:702914
...

© SecPod Technologies