{"id":"MGASA-2015-0478","summary":"Updated python-pygments packages fix security vulnerability","details":"An unsafe use of string concatenation in a shell string occurs in FontManager.\nIf the developer allows the attacker to choose the font and outputs an image,\nthe attacker can execute any shell command on the remote system. The name\nvariable injected comes from the constructor of FontManager, which is invoked\nby ImageFormatter from options (CVE-2015-8557, rhbz#1276321).\n","modified":"2026-04-16T06:23:46.507185139Z","published":"2015-12-17T20:19:23Z","upstream":["CVE-2015-8557"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0478.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17331"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2015/12/14/6"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1276321"}],"affected":[{"package":{"name":"python-pygments","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/python-pygments?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6-9.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0478.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}