Total vulnerabilities in the database
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
Software | From | Fixed in |
---|---|---|
lilypond / lilypond | 2.21.0 | 2.21.4.x |
lilypond / lilypond | - | 2.20.0.x |
fedoraproject / fedora | 31 | 31.x |
fedoraproject / fedora | 32 | 32.x |
debian / debian_linux | 10.0 | 10.0.x |
opensuse / leap | 15.2 | 15.2.x |
opensuse / backports_sle | 15.0-sp2 | 15.0-sp2.x |