3.3 LOW
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
FascinatedBox lily lily_symtab.c shorthash_for_name use after free
A vulnerability was identified in FascinatedBox lily up to 2.3. Affected by this issue is the function shorthash_for_name of the file src/lily_symtab.c. The manipulation leads to use after free. Local access is required to approach this attack. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
References
- VDB-346458 | FascinatedBox lily lily_symtab.c shorthash_for_name use after free vdb-entry technical-description
- VDB-346458 | CTI Indicators (IOB, IOC, IOA) signature permissions-required
- Submit #753164 | FascinatedBox lily main branch Use After Free third-party-advisory
- https://github.com/FascinatedBox/lily/issues/385 issue-tracking
- https://github.com/oneafter/0122/blob/main/i385/repro.lily exploit
- https://github.com/FascinatedBox/lily/ product
Affected products
- ==2.3
- ==2.2
- ==2.1
- ==2.0
Matching in nixpkgs
pkgs.lilypond
Music typesetting system
pkgs.lilypond-unstable
Music typesetting system
pkgs.lilypond-with-fonts
Music typesetting system
pkgs.openlilylib-fonts.ross
ross font for LilyPond
pkgs.gnomeExtensions.lilypad
Organize, hide, and reorder top bar icons
pkgs.openlilylib-fonts.haydn
haydn font for LilyPond
pkgs.openlilylib-fonts.bravura
bravura font for LilyPond
pkgs.openlilylib-fonts.cadence
cadence font for LilyPond
pkgs.openlilylib-fonts.gonville
gonville font for LilyPond
pkgs.openlilylib-fonts.lilyjazz
lilyjazz font for LilyPond
pkgs.openlilylib-fonts.paganini
paganini font for LilyPond
pkgs.openlilylib-fonts.profondo
profondo font for LilyPond
pkgs.openlilylib-fonts.beethoven
beethoven font for LilyPond
pkgs.openlilylib-fonts.improviso
improviso font for LilyPond
pkgs.openlilylib-fonts.scorlatti
scorlatti font for LilyPond
pkgs.lilypond-unstable-with-fonts
Music typesetting system
pkgs.openlilylib-fonts.lilyboulez
lilyboulez font for LilyPond
pkgs.openlilylib-fonts.sebastiano
sebastiano font for LilyPond
pkgs.openlilylib-fonts.lv-goldenage
lv-goldenage font for LilyPond
pkgs.openlilylib-fonts.gutenberg1939
gutenberg1939 font for LilyPond
-
nixos-unstable gutenberg1939-2316a35
- nixpkgs-unstable gutenberg1939-2316a35
- nixos-unstable-small gutenberg1939-2316a35
-
nixos-25.11 gutenberg1939-2316a35
- nixos-25.11-small gutenberg1939-2316a35
- nixpkgs-25.11-darwin gutenberg1939-2316a35
Package maintainers
-
@honnip Jung seungwoo <me@honnip.page>
-
@yurrriq Eric Bailey <eric@ericb.me>
-
@MarcWeber Marc Weber <marco-oweber@gmx.de>