HIGH🇬🇧 English

CVE-2022-45639

CVSS 7.8v3.1pub. 2023-01-24upd. 2025-04-02

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

oryginał EN
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Sleuthkit The Sleuth Kit

    APP
    Sleuthkit
    4.11.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Command Injection
CWE
Referencje

Powiązane podatności

CVE-2020-10232CRITICAL9.8PL ✓ten sam produkt

Stack buffer overflow w The Sleuth Kit – parsowanie znaczników czasu YAFFS

CVE-2020-10233CRITICAL9.1PL ✓ten sam produkt

Heap-based buffer over-read w The Sleuth Kit przy analizie NTFS

CVE-2019-14531CRITICAL9.8PL ✓ten sam produkt

Out-of-bounds read w The Sleuth Kit przy parsowaniu obrazów ISO 9660

CVE-2019-14532CRITICAL9.8PL ✓ten sam produkt

Off-by-one overwrite w The Sleuth Kit (TSK) — błędna tablica skrótów

CVE-2026-40024HIGH8.4ten sam produkt

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker t...