CVE-2022-45639

NameCVE-2022-45639
DescriptionOS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

Bogus report on srcsleuthkit: If a malformed parameter is passed, it needs to be
sanitised in the calling application

Search for package or bug name: Reporting problems