HIGH🇵🇱 Wersja polska

CVE-2022-45639

CVSS 7.8v3.1pub. 2023-01-24upd. 2025-04-02

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Sleuthkit The Sleuth Kit

    APP
    Sleuthkit
    4.11.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2020-10232CRITICAL9.8PL ✓same product

Stack buffer overflow w The Sleuth Kit – parsowanie znaczników czasu YAFFS

CVE-2020-10233CRITICAL9.1PL ✓same product

Heap-based buffer over-read w The Sleuth Kit przy analizie NTFS

CVE-2019-14531CRITICAL9.8PL ✓same product

Out-of-bounds read w The Sleuth Kit przy parsowaniu obrazów ISO 9660

CVE-2019-14532CRITICAL9.8PL ✓same product

Off-by-one overwrite w The Sleuth Kit (TSK) — błędna tablica skrótów

CVE-2026-40024HIGH8.4same product

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker t...