lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.
References
Link | Resource |
---|---|
https://gist.github.com/ert-plus/1414276e4cb5d56dd431c2f0429e4429 | Exploit Third Party Advisory |
https://github.com/exiftool/exiftool/commit/74dbab1d2766d6422bb05b033ac6634bf8d1f582 | Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2022-01-25 06:15
Updated : 2023-08-08 14:21
NVD link : CVE-2022-23935
Mitre link : CVE-2022-23935
CVE.ORG link : CVE-2022-23935
JSON object : View
Products Affected
exiftool_project
- exiftool
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')