{"id":"CVE-2023-50254","summary":"Deepin Reader RCE vulnerability due to a design flaw","details":"Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command execution via crafted docx document. This is a file overwrite vulnerability. Remote code execution (RCE) can be achieved by overwriting files like .bash_rc, .bash_login, etc. RCE will be triggered when the user opens the terminal. Version 6.0.7 contains a patch for the issue.","aliases":["GHSA-q9jr-726g-9495"],"modified":"2026-08-12T14:51:45.423986Z","published":"2023-12-22T16:49:48.977Z","related":["openSUSE-SU-2024:13536-1"],"database_specific":{"cwe_ids":["CWE-22","CWE-27"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/50xxx/CVE-2023-50254.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/50xxx/CVE-2023-50254.json"},{"type":"ADVISORY","url":"https://github.com/linuxdeepin/developer-center/security/advisories/GHSA-q9jr-726g-9495"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50254"},{"type":"FIX","url":"https://github.com/linuxdeepin/deepin-reader/commit/4db7a079fb7bd77257b1b9208a7ab26aade8fe04"},{"type":"FIX","url":"https://github.com/linuxdeepin/deepin-reader/commit/c192fd20a2fe4003e0581c3164489a89e06420c6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/linuxdeepin/deepin-reader","events":[{"introduced":"0"},{"fixed":"4db7a079fb7bd77257b1b9208a7ab26aade8fe04"},{"fixed":"c192fd20a2fe4003e0581c3164489a89e06420c6"}],"database_specific":{"cpe":"cpe:2.3:a:deepin:deepin_reader:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"6.0.7"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["6.0.6","6.0.5","6.0.4","6.0.2","6.0.1","6.0.0","5.10.29","5.10.28","5.10.27","5.10.26","5.10.11","5.10.25","5.10.24","5.10.23","5.10.22","5.10.18","5.10.15","5.10.14","5.10.10","5.10.9","5.10.8","5.10.7","5.10.6","5.10.5","5.10.4","5.10.3","5.10.2","5.9.18","5.10.1","5.9.17","5.9.15","5.9.4","5.9.6","5.9.2","5.9.0.26","5.9.0.25","5.9.0.24","5.9.1.2","5.9.0.23","5.9.0.22","5.9.0.21","5.9.0.20","5.9.0.19","5.9.0.18","5.9.0.17","5.9.0.16","5.9.0.15","5.9.0.14","5.9.0.13","5.9.0.12","5.9.0.11","5.9.0.10","5.9.0.9","5.9.0.8","5.9.0.7","5.9.0.6","5.9.0.5","5.9.0.4","5.9.0.3","5.9.0.2","5.9.0.1","5.8.0.8","5.8.0.7","5.8.0.5","5.7.0.25","5.7.0.24","5.7.0.23","5.7.0.22","5.7.0.20","5.7.0.19","5.7.0.18","5.7.0.17","5.7.0.16","5.7.0.15","5.7.0.13","5.7.0.12","5.7.0.11","5.7.0.10","5.7.0.9","5.7.0.8","5.6.7","5.6.6","5.6.5","5.6.4","5.6.3.1","5.6.3","5.6.1","5.5.5.2","5.5.5.1","5.5.5","5.5.4","5.5.3","5.5.2","5.5.1","5.5.0","5.4.9","5.4.8","5.4.7","5.4.6","5.4.5","5.4.4","5.4.3","5.4.2","5.4.1","5.4.0","5.3.9","5.3.8","5.3.7","5.3.6","5.3.5","5.3.4","5.3.2","5.3.1","5.3.0","5.2.9","5.2.8","5.2.7","5.2.6","5.2.5","5.2.4","5.2.3","5.2.2","5.2.1","5.2.0","1.0.5","1.0.2"],"database_specific":{"vanir_signatures":[{"signature_version":"v1","source":"https://github.com/linuxdeepin/deepin-reader/commit/c192fd20a2fe4003e0581c3164489a89e06420c6","target":{"file":"reader/document/Model.cpp","function":"deepin_reader::DocumentFactory::getDocument"},"deprecated":false,"digest":{"function_hash":"99317559168911753024236711830360943558","length":3525},"id":"CVE-2023-50254-5ead2631","signature_type":"Function"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/linuxdeepin/deepin-reader/commit/c192fd20a2fe4003e0581c3164489a89e06420c6","target":{"file":"reader/document/Model.cpp"},"deprecated":false,"digest":{"line_hashes":["287840479860719583676183803150162161715","72689623459492493975925408026019395309","232062186733139139157562312148349130886","108420111361074691328382336576807282303","20643342268245469805940553861084832796","246458985290276239000282885118726929908","166794536315872318796661357858088900851"],"threshold":0.9},"id":"CVE-2023-50254-f41c68de"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-50254.json","vanir_signatures_modified":"2026-08-12T14:51:45Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:H"}]}