CVE-2022-35649: Input Validation
An omitted execution parameter resulted in a remote code execution risk for sites running GhostScript versions older than 9.50.
Versions affected: 4.0 to 4.0.1, 3.11 to 3.11.7, 3.9 to 3.9.14 and earlier unsupported versions Versions fixed: 4.0.2, 3.11.8 and 3.9.15
Other sources
The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-35649?
CVE-2022-35649 is a vulnerability found in Moodle, which occurs due to improper input validation when parsing PostScript code.
How does CVE-2022-35649 impact Moodle sites?
CVE-2022-35649 poses a remote code execution risk for sites running GhostScript versions older than 9.50.
Which versions of Moodle are affected by CVE-2022-35649?
Moodle versions 3.9.0 to 3.9.15, 3.11.0 to 3.11.8, and 4.0.0 to 4.0.2 are affected by CVE-2022-35649.
How severe is CVE-2022-35649?
CVE-2022-35649 has a severity rating of 9.8 (Critical).
How can I fix CVE-2022-35649 in Moodle?
To fix CVE-2022-35649 in Moodle, it is recommended to upgrade to Moodle versions 3.9.16, 3.11.9, or 4.0.3.