Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dalvarezperez

#17113of 53,634
15.6Total CVSS
Vulnerabilities · 2
High
2
PT-2019-15244
7.8
2019-10-16
Nsa · Nsa Ghidra · CVE-2019-17664
**Name of the Vulnerable Software and Affected Versions** NSA Ghidra versions prior to 9.0.5 **Description** The issue arises when NSA Ghidra is executed from a specific path, causing the Java process working directory to be set to that path. Upon launching the Python interpreter via the "Ghidra Codebrowser > Window > Python" option, Ghidra attempts to execute the cmd.exe program from this working directory, potentially using an untrusted search path. **Recommendations** For NSA Ghidra versions prior to 9.0.5, consider updating to version 9.0.5 or later to resolve the issue. As a temporary workaround, avoid launching Ghidra from untrusted paths to minimize the risk of exploitation. Restrict access to the Python interpreter option in Ghidra until the issue is resolved.
PT-2019-15245
7.8
2019-10-16
Nsa · Ghidra · CVE-2019-17665
**Name of the Vulnerable Software and Affected Versions** Ghidra versions prior to 9.0.2 **Description** The issue arises due to the loading of `jansi.dll` from the current working directory, making it susceptible to DLL hijacking. **Recommendations** For versions prior to 9.0.2, update to version 9.0.2 or later to resolve the issue.