HIGH 7.8 Microsoft
CVE-2022-45639
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.
Microsoft Security Update 2023-Jan: OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.
Affected Products
- azl3 sleuthkit 4.12.1-1 on Azure Linux 3.0
- cbl2 sleuthkit on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-45639
- https://nvd.nist.gov/vuln/detail/CVE-2022-45639
This high severity vulnerability with a CVSS score of 7.8 was published on 2023-01-10 via Microsoft. Affected: azl3 sleuthkit 4.12.1-1 on Azure Linux 3.0, cbl2 sleuthkit on CBL Mariner 2.0.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.