Executive Summary

Informations
Name CVE-2023-39342 First vendor Publication 2023-08-08
Vendor Cve Last vendor Modification 2023-08-16

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Overall CVSS Score 3.6
Base Score 3.6 Environmental Score 3.6
impact SubScore 1.4 Temporal Score 3.6
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required None User Interaction Required
Scope Changed Confidentiality Impact None
Integrity Impact Low Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Dangerzone is software for converting potentially dangerous PDFs, office documents, or images to safe PDFs. The Dangerzone CLI (`dangerzone-cli` command) logs output from the container where the file sanitization takes place, to the user's terminal. Prior to version 0.4.2, if the container is compromised and can return attacker-controlled strings, then the attacker may be able to spoof messages in the user's terminal or change the window title. Besides logging output from containers, it also logs the names of the files it sanitizes. If these files contain ANSI escape sequences, then the same issue applies. Dangerzone is predominantly a GUI application, so this issue should leave most of our users unaffected. Nevertheless, we always suggest updating to the newest version. This issue is fixed in Dangerzone 0.4.2.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-39342

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-150 Failure to Sanitize Escape, Meta, or Control Sequences

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

Sources (Detail)

Source Url
MISC https://github.com/freedomofpress/dangerzone/pull/491
https://github.com/freedomofpress/dangerzone/releases/tag/v0.4.2
https://github.com/freedomofpress/dangerzone/security/advisories/GHSA-pvwq-6v...

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2023-08-16 21:27:25
  • Multiple Updates
2023-08-09 00:27:20
  • First insertion