Description
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-1505 | textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files. |
References
| Link | Providers |
|---|---|
| http://seclists.org/oss-sec/2016/q4/442 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T18:39:18.813Z
Reserved: 2017-04-06T00:00:00.000Z
Link: CVE-2016-10320
No data.
Status : Modified
Published: 2017-04-06T18:59:00.183
Modified: 2026-05-13T00:24:29.033
Link: CVE-2016-10320
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD