← Back

CVE-2015-8557

nvd nist
Published: Jan 8, 2016Modified: May 6, 2026

JSON object

Loading...
9.0
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 6.0
Source: NVD

Description

The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.

Affected (14)

1 product
Ubuntu Linux
1 product
Pygments
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 15.04
Version 15.10
Configuration B
10 vulnerable
Vulnerable SoftwareAffected Versions
Pygments
Version 1.2.2
Version 1.3.1
Version 1.3
Version 1.4
Version 1.5
Version 1.6
Version 1.6 rc1
Version 2.0.1
Version 2.0
Version 2.0 rc1

References (18)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.