Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 6: MGASA-2018-0412 Moderate: Lilypond Argument Injection

mageia
Calendar Grey October 26, 2018
Dist Mageia Esm H88
Newly released lilypond packages address a significant security vulnerability that may allow for remote exploitation. Urgent notice for Mageia users.
lilypond does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks (...

Summary

lilypond does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks (CVE-2017-17523).

References

- https://bugs.mageia.org/show_bug.cgi?id=23146

- - https://www.cve.org/CVERecord?id=CVE-2017-17523

Resolution

SRPMS

- 6/core/lilypond-2.19.82-1.mga6

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 26 Oct 2018
URL: https://advisories.mageia.org/MGASA-2018-0412.html
Type: security
CVE: CVE-2017-17523

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here