Junglewise Threat Intelligence

CVE-2018-3746: fagbokforlaget pdfinfojs command injection via filename parameter

CVE-2018-3746 · Severity: low · CVSS 3.1 · Published 2018-06-07

Vendors: npm.

Executive brief

pdfinfojs is a software library used to extract metadata from PDF files. A security flaw in this library allows an attacker to execute unauthorized commands on the server hosting the application. This could lead to a full system takeover, data theft, or disruption of services if the application allows users to provide or influence filenames processed by the library.

Technical details

The pdfinfojs library versions prior to 0.4.1 are vulnerable to OS command injection (CWE-78). The vulnerability exists because the library uses the 'child_process.exec' and 'child_process.execSync' functions to call the underlying 'pdfinfo' binary, passing the filename parameter without sufficient sanitization. An attacker who can control the filename passed to the constructor can inject shell metacharacters to execute arbitrary commands with the privileges of the Node.js process. The issue was resolved in version 0.4.1 by switching to 'execFile' and 'execFileSync', which do not spawn a shell.

Affected products

  • fagbokforlaget pdfinfojs < 0.4.1

Timeline

  • 2018-06-01: advisory: NVD published CVE-2018-3746
  • 2018-06-07: disclosed: GitHub Advisory GHSA-3pxp-6963-46r9 published
  • 2018-06-07: patched: Version 0.4.1 released

References