PT-2019-13451 · Nsa · Ghidra

Xiaofen9

·

Publicado

2019-07-17

·

Atualizado

2019-11-12

·

CVE-2019-13623

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghidra versions prior to 9.1
Description The issue allows path traversal in certain scenarios, potentially enabling attackers to overwrite arbitrary files. This can be achieved by using an archive with an executable file that has an initial ../ in its filename. In some cases, this could lead to arbitrary code execution if critical modules, such as the decompile module, are overwritten.
Recommendations For versions prior to 9.1, update to version 9.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of archives with executable files that have an initial ../ in their filename to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-13623

Produtos afetados

Ghidra