CVE-2023-22671: Command Injection
Published Jan 6, 2023
·Updated
Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.
Affected Software
1 affected component
NSA Ghidra<=10.2.2
Remediation
Patch Available
Event History
Jan 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-22671?
CVE-2023-22671 is classified as a high severity vulnerability due to its potential for command injection.
2
How can I fix CVE-2023-22671?
To fix CVE-2023-22671, it's recommended to upgrade Ghidra to version 10.2.3 or later, where the vulnerability is addressed.
3
What does CVE-2023-22671 affect?
CVE-2023-22671 affects NSA Ghidra version 10.2.2 and earlier, specifically related to the launch.sh script.
4
How does CVE-2023-22671 impact users?
CVE-2023-22671 allows attackers to execute arbitrary commands on the system by exploiting user input in analyzeHeadless.
5
Is CVE-2023-22671 limited to a specific operating system?
CVE-2023-22671 is specifically identified in the Linux environment within NSA Ghidra.