CVE-2018-7889

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
08/03/2018
Last modified:
12/10/2018

Description

gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:calibre-ebook:calibre:3.18.0:*:*:*:*:*:*:*