Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 6: MGASA-2018-0399 Critical: Calibre Remote Code Exec Update

mageia
Calendar Grey October 19, 2018
Dist Mageia Esm H88
MGASA-2018-0399 - Updated calibre packages fix security vulnerability Publication date: 19 Oct 2018
Updated calibre package fixes security vulnerability: gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to...

Summary

Updated calibre package fixes security vulnerability:
gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call (CVE-2018-7889).
The python-html5-parser package is a new dependency for the updated calibre package and has been included with this update.

References

- https://bugs.mageia.org/show_bug.cgi?id=22814

-

- https://www.cve.org/CVERecord?id=CVE-2018-7889

Resolution

SRPMS

- 6/core/calibre-3.27.1-2.mga6

- 6/core/python-html5-parser-0.4.4-1.1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 19 Oct 2018
URL: https://advisories.mageia.org/MGASA-2018-0399.html
Type: security
CVE: CVE-2018-7889

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here