CVE-2022-45639
sleuthkit 4.11.1 - Command Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.
Vulnerabilidad de OS Command Injection en la herramienta sleuthkit fls versión 4.11.1 permite a atacantes ejecutar comandos arbitrarios a través de un valor manipulado en el parámetro m. NOTA: terceros han cuestionado esto porque no hay ningún análisis que muestre que el comando de acento grave se ejecute fuera del contexto de la cuenta de usuario que ingresó a la línea de comando.
Sleuthkit version 4.11.1 suffers from a command injection vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-21 CVE Reserved
- 2023-01-24 CVE Published
- 2023-04-03 First Exploit
- 2024-08-03 CVE Updated
- 2024-09-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/171649/Sleuthkit-4.11.1-Command-Injection.html | ||
https://www.binaryworld.it/guidepoc.asp#CVE-2022-45639 | Broken Link |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/51225 | 2023-04-03 | |
http://www.binaryworld.it | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sleuthkit Search vendor "Sleuthkit" | The Sleuth Kit Search vendor "Sleuthkit" for product "The Sleuth Kit" | 4.11.1 Search vendor "Sleuthkit" for product "The Sleuth Kit" and version "4.11.1" | - |
Affected
|