CVE-2022-45639

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sleuthkit:the_sleuth_kit:4.11.1:*:*:*:*:*:*:*

History

21 Nov 2024, 07:29

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/171649/Sleuthkit-4.11.1-Command-Injection.html - () http://packetstormsecurity.com/files/171649/Sleuthkit-4.11.1-Command-Injection.html -
References () http://www.binaryworld.it/ - Exploit, Vendor Advisory () http://www.binaryworld.it/ - Exploit, Vendor Advisory
References () https://www.binaryworld.it/guidepoc.asp#CVE-2022-45639 - Broken Link () https://www.binaryworld.it/guidepoc.asp#CVE-2022-45639 - Broken Link

11 Apr 2024, 01:17

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de OS Command Injection en la herramienta sleuthkit fls versión 4.11.1 permite a atacantes ejecutar comandos arbitrarios a través de un valor manipulado en el parámetro m. NOTA: terceros han cuestionado esto porque no hay ningún análisis que muestre que el comando de acento grave se ejecute fuera del contexto de la cuenta de usuario que ingresó a la línea de comando.

07 Nov 2023, 03:54

Type Values Removed Values Added
Summary ** DISPUTED ** OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line. OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

Information

Published : 2023-01-24 02:15

Updated : 2024-11-21 07:29


NVD link : CVE-2022-45639

Mitre link : CVE-2022-45639

CVE.ORG link : CVE-2022-45639


JSON object : View

Products Affected

sleuthkit

  • the_sleuth_kit
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')