CVE-2018-3836: Debian Linux

High severity, CVSS 7.8. EPSS: 1.4% chance of exploitation in the next 30 days.

An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary code execution. An attacker can provide a malicious path as input to an application that passes attacker data to this function to trigger this vulnerability.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Leptonica Leptonica: version 1.74.4 only

Published 2018-04-24. Last modified 2026-06-17.