CVE-2023-50254

Published: Dic 22, 2023 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2023-55069 Aliases: GSD-2023-50254
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,3
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: changed
Confidentiality: high
Integrity: none
Availability: high

Description

AI Translation Available

Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command execution via crafted docx document. This is a file overwrite vulnerability. Remote code execution (RCE) can be achieved by overwriting files like .bash_rc, .bash_login, etc. RCE will be triggered when the user opens the terminal. Version 6.0.7 contains a patch for the issue.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0885
Percentile
0,9th
Updated

EPSS Score Trend (Last 90 Days)

22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Stable
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Execute Unauthorized Code Or Commands Modify Files Or Directories Read Files Or Directories Dos: Crash, Exit, Or Restart
Applicable Platforms
Technologies: AI/ML
View CWE Details
27

Path Traversal: 'dir/../../filename'

Draft
Common Consequences
Security Scopes Affected:
Confidentiality Integrity
Potential Impacts:
Read Files Or Directories Modify Files Or Directories
Applicable Platforms
All platforms may be affected
View CWE Details
Application

Deepin Reader by Deepin

Version Range Affected
To 6.0.7 (exclusive)
cpe:2.3:a:deepin:deepin_reader:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/linuxdeepin/deepin-reader/commit/4db7a079fb7bd77257b1b9208a7…
https://github.com/linuxdeepin/deepin-reader/commit/c192fd20a2fe4003e0581c31644…
https://github.com/linuxdeepin/developer-center/security/advisories/GHSA-q9jr-7…
https://github.com/linuxdeepin/deepin-reader/commit/4db7a079fb7bd77257b1b9208a7…
https://github.com/linuxdeepin/deepin-reader/commit/c192fd20a2fe4003e0581c31644…
https://github.com/linuxdeepin/developer-center/security/advisories/GHSA-q9jr-7…