Vulnerability Description
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Leptonica | Leptonica | 1.74.4 |
Related Weaknesses (CWE)
References
- https://bugs.debian.org/885704Mailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202312-01
- https://bugs.debian.org/885704Mailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202312-01
FAQ
What is CVE-2017-18196?
CVE-2017-18196 is a vulnerability with a CVSS score of 3.3 (LOW). Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restricti...
How severe is CVE-2017-18196?
CVE-2017-18196 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18196?
Check the references section above for vendor advisories and patch information. Affected products include: Leptonica Leptonica.