lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.
References
Link | Resource |
---|---|
https://github.com/exiftool/exiftool/commit/74dbab1d2766d6422bb05b033ac6634bf8d1f582 | Patch Third Party Advisory |
https://gist.github.com/ert-plus/1414276e4cb5d56dd431c2f0429e4429 | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-01-24 22:15
Updated : 2022-05-19 14:20
NVD link : CVE-2022-23935
Mitre link : CVE-2022-23935
JSON object : View
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Products Affected
exiftool_project
- exiftool