Bugzilla – Bug 1218382
VUL-0: CVE-2023-50254: deepin-reader: RCE via file overwrite via crafted docx document
Last modified: 2024-06-16 08:57:54 UTC
Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command execution via crafted docx document. This is a file overwrite vulnerability. Remote code execution (RCE) can be achieved by overwriting files like .bash_rc, .bash_login, etc. RCE will be triggered when the user opens the terminal. Version 6.0.7 contains a patch for the issue. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-50254
openSUSE:Backports:SLE-15-SP4:Update/deepin-reader openSUSE:Backports:SLE-15-SP5:Update/deepin-reader openSUSE:Factory deepin-reader need updates
Will fix it on Leap 15.5 and Tumbleweed. Won't fix it on Leap 15.4, because it does not exist on Leap 15.4
This is an autogenerated message for OBS integration: This bug (1218382) was mentioned in https://build.opensuse.org/request/show/1135091 Backports:SLE-15-SP5 / deepin-reader https://build.opensuse.org/request/show/1135094 Factory / deepin-reader
Fixed