Executive brief
pdfinfojs is a software library used to extract metadata from PDF files. A security flaw in this library allows an attacker to execute unauthorized commands on the server hosting the application. This could lead to a full system takeover, data theft, or disruption of services if the application allows users to provide or influence filenames processed by the library.
Technical details
The pdfinfojs library versions prior to 0.4.1 are vulnerable to OS command injection (CWE-78). The vulnerability exists because the library uses the 'child_process.exec' and 'child_process.execSync' functions to call the underlying 'pdfinfo' binary, passing the filename parameter without sufficient sanitization. An attacker who can control the filename passed to the constructor can inject shell metacharacters to execute arbitrary commands with the privileges of the Node.js process. The issue was resolved in version 0.4.1 by switching to 'execFile' and 'execFileSync', which do not spawn a shell.
Affected products
- fagbokforlaget pdfinfojs < 0.4.1
Timeline
- 2018-06-01: advisory: NVD published CVE-2018-3746
- 2018-06-07: disclosed: GitHub Advisory GHSA-3pxp-6963-46r9 published
- 2018-06-07: patched: Version 0.4.1 released