muyuankai

3 exploits Active since Dec 2023
CVE-2023-50254 WRITEUP CRITICAL WRITEUP
deepin_reader < 6.0.7 - Remote Code Execution via Crafted DOCX File
Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command execution via crafted docx document. This is a file overwrite vulnerability. Remote code execution (RCE) can be achieved by overwriting files like .bash_rc, .bash_login, etc. RCE will be triggered when the user opens the terminal. Version 6.0.7 contains a patch for the issue.
CVSS 9.3
CVE-2023-50254 WRITEUP CRITICAL WRITEUP
deepin_reader < 6.0.7 - Remote Code Execution via Crafted DOCX File
Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command execution via crafted docx document. This is a file overwrite vulnerability. Remote code execution (RCE) can be achieved by overwriting files like .bash_rc, .bash_login, etc. RCE will be triggered when the user opens the terminal. Version 6.0.7 contains a patch for the issue.
CVSS 9.3
CVE-2023-50255 WRITEUP CRITICAL WRITEUP
deepin-compressor < 5.12.21 - Path Traversal and Remote Code Execution via Crafted Archive
Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerability in deepin-compressor that can be exploited to achieve Remote Command Execution on the target system upon opening crafted archives. Users are advised to update to version 5.12.21 which addresses the issue. There are no known workarounds for this vulnerability.
CVSS 9.3