PT-2023-15408 · Mintty · Mintty

David Leadbeater

·

Publicado

2023-10-19

·

Atualizado

2023-10-25

·

CVE-2022-47583

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mintty versions prior to 3.6.3
Description The issue allows code execution via unescaped output to the terminal. This is due to terminal character injection in Mintty.
Recommendations For versions prior to 3.6.3, update to version 3.6.3 or later to resolve the issue. As a temporary workaround, consider restricting the output to the terminal to minimize the risk of code execution.

Exploit

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-47583

Produtos afetados

Mintty