PT-2025-39207 · Cryptolib · Cryptolib

Luiginoc

·

Published

2025-09-23

·

Updated

2025-11-29

·

CVE-2025-59534

CVSS v3.1
7.8
VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CryptoLib versions prior to 1.4.2
Description CryptoLib is a software solution utilizing the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) for secure communications between spacecraft and ground stations. A command injection issue exists in the
initialize kerberos keytab file login()
function due to the direct interpolation of user-controlled input into a shell command executed via the
system()
function without proper sanitization or validation. This allows for potential unauthorized command execution.
Recommendations Update CryptoLib to version 1.4.2 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-59534
GHSA-JW5C-58HR-M3V3

Affected Products

Cryptolib