Vulnerability Description
The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 12.04 |
| Pygments | Pygments | 1.2.2 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/133823/Pygments-FontManager._get_nix_font_p
- http://seclists.org/fulldisclosure/2015/Oct/4
- http://www.debian.org/security/2016/dsa-3445
- http://www.openwall.com/lists/oss-security/2015/12/14/17
- http://www.openwall.com/lists/oss-security/2015/12/14/6
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.ubuntu.com/usn/USN-2862-1
- https://bitbucket.org/birkenfeld/pygments-main/pull-requests/501/fix-shell-injecVendor Advisory
- https://security.gentoo.org/glsa/201612-05
- http://packetstormsecurity.com/files/133823/Pygments-FontManager._get_nix_font_p
- http://seclists.org/fulldisclosure/2015/Oct/4
- http://www.debian.org/security/2016/dsa-3445
- http://www.openwall.com/lists/oss-security/2015/12/14/17
- http://www.openwall.com/lists/oss-security/2015/12/14/6
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
FAQ
What is CVE-2015-8557?
CVE-2015-8557 is a vulnerability with a CVSS score of 9.0 (CRITICAL). The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
How severe is CVE-2015-8557?
CVE-2015-8557 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-8557?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Pygments Pygments.