CVE-2018-7247

CRITICAL

leptonica < 1.75.3 - Buffer Overflow in pixHtmlViewer

Title source: llm
STIX 2.1

Description

An issue was discovered in pixHtmlViewer in prog/htmlviewer.c in Leptonica before 1.75.3. Unsanitized input (rootname) can overflow a buffer, leading potentially to arbitrary code execution or possibly unspecified other impact.

Scores

CVSS v3 9.8
EPSS 0.0253
EPSS Percentile 82.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
leptonica/leptonica < 1.75.3
Published Feb 19, 2018
Tracked Since Feb 18, 2026