CVE-2015-8557
08.01.2016, 20:59
The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
Vendor | Product | Version |
---|---|---|
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 15.04 |
canonical | ubuntu_linux | 15.10 |
pygments | pygments | 1.2.2 |
pygments | pygments | 1.3 |
pygments | pygments | 1.3.1 |
pygments | pygments | 1.4 |
pygments | pygments | 1.5 |
pygments | pygments | 1.6 |
pygments | pygments | 1.6:rc1 |
pygments | pygments | 2.0 |
pygments | pygments | 2.0:rc1 |
pygments | pygments | 2.0.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References