Mageia 2020-0414: lilypond security update
Summary
It was discovered that Lilypond, a program for typesetting sheet music, did
not restrict the inclusion of Postscript and SVG commands when operating in
safe mode, which could result in the execution of arbitrary code when rendering
a typesheet file with embedded Postscript code.
(CVE-2020-17353)
References
- https://bugs.mageia.org/show_bug.cgi?id=27174
- https://www.debian.org/security/2020/dsa-4756
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/QG2JUV4UTIA27JUE6IZLCEFP5PYSFPF4/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17353
Resolution
MGASA-2020-0414 - Updated lilypond package fixes a security vulnerability
SRPMS
- 7/core/lilypond-2.19.83-1.1.mga7