PT-2023-22999 · Mutagen+1 · Mutagen+1

Xenoscopic

·

Publicado

2023-05-05

·

Atualizado

2024-08-20

·

CVE-2023-30844

CVSS v3.1

3.0

Baixa

VetorAV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mutagen versions prior to 0.16.6 Mutagen versions prior to 0.17.1 mutagen-compose versions prior to 0.17.1
Description The issue affects Mutagen's list and monitor commands, making them susceptible to control characters provided by remote endpoints. This could cause terminal corruption if these characters are present in error messages or file paths/names. The issue could be used as an attack vector when synchronizing with untrusted remote endpoints or forwarding to/from them. On older systems with vulnerable terminals, it could theoretically lead to code execution.
Recommendations For Mutagen versions prior to 0.16.6, update to version 0.16.6 or later to resolve the issue. For Mutagen versions prior to 0.17.1, update to version 0.17.1 or later to resolve the issue. For mutagen-compose versions prior to 0.17.1, update to version 0.17.1 or later to resolve the issue. As a temporary workaround, avoid synchronizing untrusted files or interacting with untrusted remote endpoints to mitigate the risk.

Exploit

Correção

Improper Encoding or Escaping of Output

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-30844
GHSA-JMP2-WC4P-WFH2
GO-2023-1764

Produtos afetados

Mutagen
Mutagen-Compose