PT-2022-5146 · Moodle+3 · Moodle+3
Nick Wojciechowski
·
Published
2020-11-08
·
Updated
2024-03-06
·
CVE-2022-35649
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moodle (affected versions not specified)
GhostScript versions prior to 9.50
Description
The issue occurs due to improper input validation when parsing PostScript code, resulting in a remote code execution risk. An omitted execution parameter allows for the exploitation of this issue, which may lead to the complete compromise of the vulnerable system. Successful exploitation can enable a remote attacker to execute arbitrary code.
Recommendations
For Moodle, update GhostScript to version 9.50 or later to resolve the issue.
As a temporary workaround, consider disabling the parsing of PostScript code until a patch is available.
Restrict access to the PostScript parsing functionality to minimize the risk of exploitation.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Ghostscript
Moodle
Red Os