Vulnerability Name: | CVE-2015-8557 (CCN-106924) | ||||||||||||||||
Assigned: | 2015-09-28 | ||||||||||||||||
Published: | 2015-09-28 | ||||||||||||||||
Updated: | 2017-07-01 | ||||||||||||||||
Summary: | The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name. | ||||||||||||||||
CVSS v3 Severity: | 9.0 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) 7.8 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.2 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
| ||||||||||||||||
Vulnerability Type: | CWE-78 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-8557 Source: MISC Type: UNKNOWN http://packetstormsecurity.com/files/133823/Pygments-FontManager._get_nix_font_path-Shell-Injection.html Source: CCN Type: Pygments Web site Pygments Source: CCN Type: Full-Disclosure Mailing List, Mon, 28 Sep 2015 17:27:41 -0000 Shell Injection in Pygments FontManager._get_nix_font_path Source: FULLDISC Type: UNKNOWN 20151001 Shell Injection in Pygments FontManager._get_nix_font_path Source: CCN Type: oss-sec Mailing List, Mon, 14 Dec 2015 15:09:39 +0100 CVE request: Shell Injection in Pygments FontManager._get_nix_font_path Source: DEBIAN Type: UNKNOWN DSA-3445 Source: MLIST Type: UNKNOWN [oss-security] 20151214 Re: CVE request: Shell Injection in Pygments FontManager._get_nix_font_path Source: MLIST Type: UNKNOWN [oss-security] 20151214 CVE request: Shell Injection in Pygments FontManager._get_nix_font_path Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html Source: UBUNTU Type: UNKNOWN USN-2862-1 Source: MISC Type: Vendor Advisory https://bitbucket.org/birkenfeld/pygments-main/pull-requests/501/fix-shell-injection-in/diff Source: CCN Type: Red Hat Bugzilla Bug 1276321 (CVE-2015-8557) CVE-2015-8557 python-pygments: Shell injection in FontManager._get_nix_font_path Source: XF Type: UNKNOWN pygments-cve20158557-command-exec(106924) Source: GENTOO Type: UNKNOWN GLSA-201612-05 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-8557 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |