Vulnerabilities > CVE-2020-17353

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
lilypond
fedoraproject
debian
opensuse
critical

Summary

scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.

Vulnerable Configurations

Part Description Count
Application
Lilypond
60
Application
Opensuse
1
OS
Fedoraproject
2
OS
Debian
1
OS
Opensuse
1