Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "leptonica-progs",
"binary_version": "1.73-1ubuntu0.1~esm1"
},
{
"binary_name": "liblept5",
"binary_version": "1.73-1ubuntu0.1~esm1"
},
{
"binary_name": "libleptonica-dev",
"binary_version": "1.73-1ubuntu0.1~esm1"
}
]
}