CVE-2022-45145: OS Command Injection
Published Dec 10, 2022
·Updated
egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.
Affected Software
1 affected component
Call-cc Chicken>=5.0.0<5.3.1
Remediation
Event History
Dec 10, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-45145?
CVE-2022-45145 has a high severity level due to the potential for arbitrary OS command execution.
2
How do I fix CVE-2022-45145?
To fix CVE-2022-45145, upgrade CHICKEN to version 5.3.1 or later.
3
What versions of CHICKEN are affected by CVE-2022-45145?
CVE-2022-45145 affects CHICKEN versions 5.0.0 to 5.3.0.
4
What kind of attacks can exploit CVE-2022-45145?
CVE-2022-45145 can be exploited to execute arbitrary OS commands during package installation.
5
Is there a workaround for CVE-2022-45145 if I cannot upgrade?
As of now, there are no known effective workarounds for CVE-2022-45145 other than upgrading.