CVE-2015-8557

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
08/01/2016
Last modified:
12/04/2025

Description

The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
cpe:2.3:a:pygments:pygments:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:pygments:pygments:1.3:*:*:*:*:*:*:*
cpe:2.3:a:pygments:pygments:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:pygments:pygments:1.4:*:*:*:*:*:*:*
cpe:2.3:a:pygments:pygments:1.5:*:*:*:*:*:*:*
cpe:2.3:a:pygments:pygments:1.6:*:*:*:*:*:*:*
cpe:2.3:a:pygments:pygments:1.6:rc1:*:*:*:*:*:*
cpe:2.3:a:pygments:pygments:2.0:*:*:*:*:*:*:*
cpe:2.3:a:pygments:pygments:2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:pygments:pygments:2.0.1:*:*:*:*:*:*:*