CVE-2021-45845

NameCVE-2021-45845
DescriptionThe Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted FCStd document.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
ReferencesDSA-5229-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freecad (PTS)buster0.18~pre1+dfsg1-5fixed
buster (security)0.18~pre1+dfsg1-5+deb10u1fixed
bullseye0.19.1+dfsg1-2vulnerable
bullseye (security)0.19.1+dfsg1-2+deb11u1fixed
bookworm, sid0.20.1+dfsg1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freecadsourcestretch(not affected)
freecadsourcebuster(not affected)
freecadsourcebullseye0.19.1+dfsg1-2+deb11u1DSA-5229-1
freecadsource(unstable)0.19.4+dfsg1-1

Notes

[buster] - freecad <not-affected> (Vulnerable code introduced in 0.19)
[stretch] - freecad <not-affected> (Vulnerable code introduced in 0.19)
https://github.com/FreeCAD/FreeCAD/pull/5306
Introduced by: https://github.com/FreeCAD/FreeCAD/commit/dfc4e53f67785841b9bf106a79ccf5a6f7b0d524
Fixed by: https://github.com/FreeCAD/FreeCAD/commit/169eb655f30180b95e5923be2eb3bc4de6e02406 (master)
Fixed by: https://github.com/FreeCAD/FreeCAD/commit/a73f442f88725e08f36a3614e690bdef24c3dee3 (0.19.4)
https://tracker.freecad.org/view.php?id=4810

Search for package or bug name: Reporting problems