CVE-2022-29583

service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. NOTE: this finding could not be reproduced by its original reporter or by others.
References
Link Resource
https://github.com/kardianos/service/pull/290 Patch Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:service_project:service:-:*:*:*:*:go:*:*

History

No history.

Information

Published : 2022-04-22 16:15

Updated : 2024-05-17 02:08


NVD link : CVE-2022-29583

Mitre link : CVE-2022-29583

CVE.ORG link : CVE-2022-29583


JSON object : View

Products Affected

service_project

  • service

microsoft

  • windows
CWE
CWE-426

Untrusted Search Path