CVE-2022-45639

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sleuthkit:the_sleuth_kit:4.11.1:*:*:*:*:*:*:*

History

21 Nov 2024, 07:29

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/171649/Sleuthkit-4.11.1-Command-Injection.html - () http://packetstormsecurity.com/files/171649/Sleuthkit-4.11.1-Command-Injection.html -
References () http://www.binaryworld.it/ - Exploit, Vendor Advisory () http://www.binaryworld.it/ - Exploit, Vendor Advisory
References () https://www.binaryworld.it/guidepoc.asp#CVE-2022-45639 - Broken Link () https://www.binaryworld.it/guidepoc.asp#CVE-2022-45639 - Broken Link

07 Nov 2023, 03:54

Type Values Removed Values Added
Summary ** DISPUTED ** OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line. OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

03 Apr 2023, 20:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/171649/Sleuthkit-4.11.1-Command-Injection.html -

Information

Published : 2023-01-24 02:15

Updated : 2025-04-02 15:15


NVD link : CVE-2022-45639

Mitre link : CVE-2022-45639

CVE.ORG link : CVE-2022-45639


JSON object : View

Products Affected

sleuthkit

  • the_sleuth_kit
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')