Debian Security Advisory

DLA-1284-1 leptonlib -- LTS security update

Date Reported:
15 Feb 2018
Affected Packages:
leptonlib
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 889759.
In Mitre's CVE dictionary: CVE-2018-3836.
More information:

Talosintelligence discovered a command injection vulnerability in the gplotMakeOutput function of leptonlib. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary code execution. An attacker can provide a malicious path as input to an application that passes attacker data to this function to trigger this vulnerability.

For Debian 7 Wheezy, these problems have been fixed in version 1.69-3.1+deb7u1.

We recommend that you upgrade your leptonlib packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS