Executive brief
dawnsparks-node-tesseract is a Node.js library for optical character recognition (OCR) that processes images to extract text. The library contained a critical vulnerability in how it invoked system processes, allowing attackers to execute arbitrary code on systems using the library. This could lead to complete system compromise, data theft, and service disruption.
Technical details
The vulnerability is a command injection flaw (CWE-77) in the child_process handling within dawnsparks-node-tesseract versions before 0.4.1. The library used the insecure exec() function from Node.js child_process module, which spawns a shell and is vulnerable to command injection when passed unsanitized input. An attacker able to provide input to the OCR processing function could inject shell metacharacters to execute arbitrary system commands with the privileges of the Node.js process. The fix involved replacing exec() with execFile(), which does not spawn a shell and mitigates shell metacharacter injection. Network reachability and the ability to provide input to image processing functions are the primary preconditions.
Affected products
- Rona Dini Hari dawnsparks-node-tesseract before 0.4.1
Timeline
- 2023-04-24: disclosed
- 2023-03-07: patched: Fix committed on 2023-03-07, formal advisory published 2023-04-24