Bug#898439: leptonlib: CVE-2018-7442

2018-05-11 Thread Salvatore Bonaccorso
Hi, On Fri, May 11, 2018 at 12:01:02PM -0700, Jeff Breidenbach wrote: > Believed fixed in Debian package 1.76.0-1 > > Status of various vulnerabilities, as per upstream: > > * CVE-2018-7442: potential injection attack because '/' is allowed > in gplot rootdir. >

Bug#898439: leptonlib: CVE-2018-7442

2018-05-11 Thread Jeff Breidenbach
Believed fixed in Debian package 1.76.0-1 Status of various vulnerabilities, as per upstream: * CVE-2018-7442: potential injection attack because '/' is allowed in gplot rootdir. Functions using this command have been disabled by default in the

Bug#898439: leptonlib: CVE-2018-7442

2018-05-11 Thread Salvatore Bonaccorso
Source: leptonlib Version: 1.75.3-1 Severity: important Tags: security upstream Hi, The following vulnerability was published for leptonlib, I think this one was never reported yet directly to the BTS (nor upstream?). CVE-2018-7442[0]: | An issue was discovered in Leptonica through 1.75.3. The