{ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2020-17354", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scope, as demonstrated by dangerous Scheme code in a .ly file that causes arbitrary code execution during conversion to a different file format. NOTE: in 2.24 and later versions, safe mode is removed, and the product no longer tries to block code execution when external files are used." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "url": "http://lilypond.org/doc/v2.18/Documentation/usage/command_002dline-usage", "refsource": "MISC", "name": "http://lilypond.org/doc/v2.18/Documentation/usage/command_002dline-usage" }, { "refsource": "MISC", "name": "https://phabricator.wikimedia.org/T259210", "url": "https://phabricator.wikimedia.org/T259210" }, { "refsource": "MISC", "name": "https://www.mediawiki.org/wiki/Extension:Score/2021_security_advisory", "url": "https://www.mediawiki.org/wiki/Extension:Score/2021_security_advisory" }, { "refsource": "MISC", "name": "https://tracker.debian.org/news/1249694/accepted-lilypond-2221-1-source-into-unstable/", "url": "https://tracker.debian.org/news/1249694/accepted-lilypond-2221-1-source-into-unstable/" }, { "refsource": "CONFIRM", "name": "https://gitlab.com/lilypond/lilypond/-/merge_requests/1522", "url": "https://gitlab.com/lilypond/lilypond/-/merge_requests/1522" }, { "refsource": "MISC", "name": "https://lilypond.org/download.html", "url": "https://lilypond.org/download.html" }, { "refsource": "FEDORA", "name": "FEDORA-2023-fb8bc496c2", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ST5BLLQ4GDME3SN7UE5OMNE5GZE66X4Y/" }, { "refsource": "FEDORA", "name": "FEDORA-2023-6edb8fab0d", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/K43PF6VGFJNNGAPY57BW3VMEFFOSMRLF/" } ] } }