From 2daf0031e3a518233405de9cc2911de2fb937221 Mon Sep 17 00:00:00 2001 From: Rafael Grether Date: Sat, 11 Jun 2022 18:10:36 +0000 Subject: [PATCH 2/2] ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection Changes to be committed: modified: vuln-2022.xml --- security/vuxml/vuln-2022.xml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/security/vuxml/vuln-2022.xml b/security/vuxml/vuln-2022.xml index 37fbce5754b7..10b7510c7ddb 100644 --- a/security/vuxml/vuln-2022.xml +++ b/security/vuxml/vuln-2022.xml @@ -1,3 +1,29 @@ + + Security Vulnerability found in ExifTool leading to RCE + + + p5-Image-ExifTool + 12.38 + + + + +

Debian Security tracker reports:

+
+

ExifTool.pm in ExifTool before 12.38 mishandles a file special characters check, leading to command injection

+
+ +
+ + CVE-2022-23935 + https://www.cvedetails.com/cve/CVE-2022-23935 + + + 2022-01-25 + 2022-06-11 + +
+ XFCE -- Allows executing malicious .desktop files pointing to remote code -- 2.36.1