CVE-2023-50254
Deepin Reader RCE vulnerability due to a design flaw
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command execution via crafted docx document. This is a file overwrite vulnerability. Remote code execution (RCE) can be achieved by overwriting files like .bash_rc, .bash_login, etc. RCE will be triggered when the user opens the terminal. Version 6.0.7 contains a patch for the issue.
El software de lectura de documentos predeterminado de Deepin Linux, `deepin-reader`, sufre una grave vulnerabilidad en versiones anteriores a la 6.0.7 debido a un fallo de diseño que conduce a la ejecución remota de comandos a través de un documento docx manipulado. Esta es una vulnerabilidad de sobrescritura de archivos. La ejecución remota de código (RCE) se puede lograr sobrescribiendo archivos como .bash_rc, .bash_login, etc. RCE se activará cuando el usuario abra la terminal. La versión 6.0.7 contiene un parche para el problema.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-12-05 CVE Reserved
- 2023-12-22 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-08-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-27: Path Traversal: 'dir/../../filename'
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/linuxdeepin/developer-center/security/advisories/GHSA-q9jr-726g-9495 | 2024-08-02 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Deepin Search vendor "Deepin" | Deepin Reader Search vendor "Deepin" for product "Deepin Reader" | < 6.0.7 Search vendor "Deepin" for product "Deepin Reader" and version " < 6.0.7" | - |
Affected
|