CVE-2018-3836
PoC —CVSS 3.1
7.8 high
EPSS
1%p71
Published
()
Modified
Description
An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary code execution. An attacker can provide a malicious path as input to an application that passes attacker data to this function to trigger this vulnerability.
In the news0 stories
No ingested article mentions this CVE yet.