First published: Sun Nov 06 2022(Updated: )
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mahara Mahara | >=21.04.0<21.04.7 | |
Mahara Mahara | >=21.10.0<21.10.5 | |
Mahara Mahara | >=22.04.0<22.04.3 | |
Mahara Mahara | =22.10.0-rc1 | |
Canonical Ubuntu Linux | =18.04 | |
All of | ||
Any of | ||
Mahara Mahara | >=21.04.0<21.04.7 | |
Mahara Mahara | >=21.10.0<21.10.5 | |
Mahara Mahara | >=22.04.0<22.04.3 | |
Mahara Mahara | =22.10.0-rc1 | |
Canonical Ubuntu Linux | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44544 is a vulnerability in Mahara before version 21.04.7, 21.10.5, 22.04.3, and 22.10.0 that potentially allows a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.
This vulnerability can be exploited by triggering a PDF export on a Mahara site running on Ubuntu where the flag -dSAFER is not set with Ghostscript.
CVE-2022-44544 has a severity rating of 9.8 (Critical).
Mahara versions before 21.04.7, 21.10.5, 22.04.3, and 22.10.0 are affected by CVE-2022-44544.
To fix CVE-2022-44544, update Mahara to version 21.04.7, 21.10.5, 22.04.3, or 22.10.0.