CVE-2018-7889

Description

gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
11.035

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2018-7889 are affected in Calibre (x64) 3.18.0Windows
Vulnerability CVE-2018-7889 are affected in Calibre 3.18.0Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-342947Calibre (x64) (7.21.0)
PATCH-325330Calibre (5.44.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234