Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8: MGASA-2022-0325 Moderate FreeCAD Command Injection

mageia
Calendar Grey September 16, 2022
Dist Mageia Esm H88
The latest FreeCAD patch in Mageia 8 resolves an inadequate input validation vulnerability that could lead to potential command injection threats. Discover further details.
Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename

Summary

Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename. (CVE-2021-45844)

References

- https://bugs.mageia.org/show_bug.cgi?id=30137

- https://lists.debian.org/debian-lts-announce/2022/03/msg00005.html

- https://lists.debian.org/debian-lts-announce/2022/08/msg00008.html

- https://www.cve.org/CVERecord?id=CVE-2021-45844

Resolution

SRPMS

- 8/core/freecad-0.18.6-1.3.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 16 Sep 2022
URL: https://advisories.mageia.org/MGASA-2022-0325.html
Type: security
CVE: CVE-2021-45844

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here