CVE-2019-13623
Last modified
CVE-2019-13623 is a vulnerability of currently unknown severity. In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows attackers to overwrite arbitrary files in scenarios where an intermediate analysis result is archived for sharing with other persons. EPSS estimates a 4.96% chance of exploitation in the next 30 days.
Description
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows attackers to overwrite arbitrary files in scenarios where an intermediate analysis result is archived for sharing with other persons. To achieve arbitrary code execution, one approach is to overwrite some critical Ghidra modules, e.g., the decompile module.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nsa | Ghidra | <= 9.0.4 |
References
- http://blog.fxiao.me/ghidra/Exploit, Third Party Advisory
- https://github.com/NationalSecurityAgency/ghidra/issues/789Exploit, Third Party Advisory
- http://blog.fxiao.me/ghidra/Exploit, Third Party Advisory
- https://github.com/NationalSecurityAgency/ghidra/issues/789Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13623?
How severe is CVE-2019-13623?
How do I fix CVE-2019-13623?
Are you affected by CVE-2019-13623?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
