GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://gitlab.gnome.org/GNOME/ocrfeeder/-/merge_requests/13 | patch third party advisory issue tracking |
https://gitlab.gnome.org/GNOME/ocrfeeder/-/commit/5286120c8bc8b7ba74e0f9b19b5262b509f38cee | patch |
https://gitlab.gnome.org/GNOME/ocrfeeder/-/issues/20 | patch exploit third party advisory issue tracking |