2023-10-16
ALT-BU-2023-6383-1
Branch sisyphus update bulletin.
Closed bugs
mtr version update
Package system-monitoring-center updated to version 2.25.1-alt1 for branch sisyphus in task 331822.
Closed bugs
Версия уже устарела
Closed bugs
libfmt: new version
Closed vulnerabilities
Published: 2023-04-16
Modified: 2025-02-06
Modified: 2025-02-06
CVE-2020-17354
LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scope, as demonstrated by dangerous Scheme code in a .ly file that causes arbitrary code execution during conversion to a different file format. NOTE: in 2.24 and later versions, safe mode is removed, and the product no longer tries to block code execution when external files are used.
Severity: HIGH (8.6)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
References:
- http://lilypond.org/doc/v2.18/Documentation/usage/command_002dline-usage
- http://lilypond.org/doc/v2.18/Documentation/usage/command_002dline-usage
- https://gitlab.com/lilypond/lilypond/-/merge_requests/1522
- https://gitlab.com/lilypond/lilypond/-/merge_requests/1522
- https://lilypond.org/download.html
- https://lilypond.org/download.html
- FEDORA-2023-6edb8fab0d
- FEDORA-2023-6edb8fab0d
- FEDORA-2023-fb8bc496c2
- FEDORA-2023-fb8bc496c2
- https://phabricator.wikimedia.org/T259210
- https://phabricator.wikimedia.org/T259210
- https://tracker.debian.org/news/1249694/accepted-lilypond-2221-1-source-into-unstable/
- https://tracker.debian.org/news/1249694/accepted-lilypond-2221-1-source-into-unstable/
- https://www.mediawiki.org/wiki/Extension:Score/2021_security_advisory
- https://www.mediawiki.org/wiki/Extension:Score/2021_security_advisory