CVE-2022-29583

service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. NOTE: this finding could not be reproduced by its original reporter or by others.
References
Link Resource
https://github.com/kardianos/service/pull/290 Patch Third Party Advisory
https://github.com/kardianos/service/pull/290 Patch Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:service_project:service:-:*:*:*:*:go:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:59

Type Values Removed Values Added
References () https://github.com/kardianos/service/pull/290 - Patch, Third Party Advisory () https://github.com/kardianos/service/pull/290 - Patch, Third Party Advisory

07 Nov 2023, 03:46

Type Values Removed Values Added
Summary ** DISPUTED ** service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. NOTE: this finding could not be reproduced by its original reporter or by others. service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. NOTE: this finding could not be reproduced by its original reporter or by others.

Information

Published : 2022-04-22 16:15

Updated : 2024-11-21 06:59


NVD link : CVE-2022-29583

Mitre link : CVE-2022-29583

CVE.ORG link : CVE-2022-29583


JSON object : View

Products Affected

microsoft

  • windows

service_project

  • service
CWE
CWE-426

Untrusted Search Path