CVE-2015-8557: OS Command Injection
Published Jan 8, 2016
·Updated
The FontManager.getnixfontpath function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
Affected Software
15 affected componentsFixes available
pip/Pygments>=1.2.2<2.1
2.1
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
Canonical Ubuntu Linux=15.10
Pygments Pygments=1.2.2
Pygments Pygments=1.3
Pygments Pygments=1.3.1
Pygments Pygments=1.4
Pygments Pygments=1.5
Pygments Pygments=1.6
Pygments Pygments=1.6-rc1
Pygments Pygments=2.0
Pygments Pygments=2.0-rc1
Pygments Pygments=2.0.1
Event History
Jan 8, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·02:37 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-8557?
CVE-2015-8557 has a medium severity level due to the potential for remote code execution through shell metacharacters in font names.
2
How do I fix CVE-2015-8557?
To fix CVE-2015-8557, upgrade Pygments to version 2.1 or later.
3
Which versions of Pygments are affected by CVE-2015-8557?
CVE-2015-8557 affects Pygments versions 1.2.2 to 2.0.2.
4
What types of attacks can exploit CVE-2015-8557?
CVE-2015-8557 can be exploited through remote attacks that inject arbitrary commands into font names.
5
What platforms are impacted by CVE-2015-8557?
CVE-2015-8557 impacts systems running vulnerable versions of Pygments, particularly on Ubuntu 12.04, 14.04, 15.04, and 15.10.