PT-2023-9543 · Pandoc+2 · Pandoc+2

CVE-2023-38745

·

Publicado

2023-07-25

·

Atualizado

2025-11-04

CVSS v3.1

6.3

Média

VetorAV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pandoc versions prior to 3.1.6
Description The issue is related to insufficient input validation in the Pandoc library, which can be exploited to create or overwrite arbitrary files in the system. This can be achieved by using the --extract-media option or outputting to PDF format, allowing an attacker to create or overwrite files depending on the privileges of the process running Pandoc. The issue only affects systems that pass untrusted user input to Pandoc and allow it to produce a PDF or use the --extract-media option.
Recommendations For versions prior to 3.1.6, update to version 3.1.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of the --extract-media option and avoid outputting to PDF format until the update is applied. Additionally, restrict access to untrusted user input to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2025-8475
BDU:2024-08375
CVE-2023-38745
DLA-3507-1
OPENSUSE-SU-2024:13246-1

Produtos afetados

Alt Linux
Pandoc
Red Os