Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA...
Critical severity
Unreviewed
Published
Jan 6, 2023
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Jan 6, 2023
Published to the GitHub Advisory Database
Jan 6, 2023
Last updated
Jan 28, 2023
Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.
References