CVE-2020-17353

Source
https://cve.org/CVERecord?id=CVE-2020-17353
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-17353.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-17353
Downstream
Related
Published
2020-08-05T14:15:12.810Z
Modified
2026-02-19T01:40:08.111505Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.

References

Affected packages

Git / github.com/lilypond/lilypond

Affected ranges

Type
GIT
Repo
https://github.com/lilypond/lilypond
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
Last affected

Affected versions

release/2.*
release/2.21.0-1
release/2.21.1-1
release/2.21.2-1
release/2.21.3-1
release/2.21.4-1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-17353.json"