CVE-2021-45844
published 2022-01-25CVE-2021-45844: Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.10%
62.5th percentile
Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | freecad | < freecad 0.19.4+dfsg1-1 (bookworm) | freecad 0.19.4+dfsg1-1 (bookworm) |
| freecadweb | freecad | — | — |
| freecadweb | freecad | >= 0 < 0.19.1+dfsg1-2+deb11u1 | 0.19.1+dfsg1-2+deb11u1 |
| freecadweb | freecad | >= 0 < 0.19.4+dfsg1-1 | 0.19.4+dfsg1-1 |
| freecadweb | freecad | >= 0 < 0.19.4+dfsg1-1 | 0.19.4+dfsg1-1 |
| freecadweb | freecad | >= 0 < 0.19.4+dfsg1-1 | 0.19.4+dfsg1-1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-45844: freecad - Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 ...
vendor_debian·2021·CVSS 7.8
CVE-2021-45844 [HIGH] CVE-2021-45844: freecad - Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 ...
Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.
Scope: local
bookworm: resolved (fixed in 0.19.4+dfsg1-1)
bullseye: resolved (fixed in 0.19.1+dfsg1-2+deb11u1)
forky: resolved (fixed in 0.19.4+dfsg1-1)
sid: resolved (fixed in 0.19.4+dfsg1-1)
trixie: resolved (fixed in 0.19.4+dfsg1-1)
GHSA
GHSA-344m-62pc-2wvw: Improper sanitization in the invocation of ODA File Converter from FreeCAD 0
ghsa_unreviewed·2022-01-26
CVE-2021-45844 [HIGH] CWE-78 GHSA-344m-62pc-2wvw: Improper sanitization in the invocation of ODA File Converter from FreeCAD 0
Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.
OSV
CVE-2021-45844: Improper sanitization in the invocation of ODA File Converter from FreeCAD 0
osv·2022-01-25·CVSS 7.8
CVE-2021-45844 [HIGH] CVE-2021-45844: Improper sanitization in the invocation of ODA File Converter from FreeCAD 0
Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://forum.freecadweb.org/viewtopic.php?t=64733https://lists.debian.org/debian-lts-announce/2022/03/msg00004.htmlhttps://lists.debian.org/debian-lts-announce/2022/08/msg00008.htmlhttps://tracker.freecad.org/view.php?id=4809https://www.debian.org/security/2022/dsa-5229https://forum.freecadweb.org/viewtopic.php?t=64733https://lists.debian.org/debian-lts-announce/2022/03/msg00004.htmlhttps://lists.debian.org/debian-lts-announce/2022/08/msg00008.htmlhttps://tracker.freecad.org/view.php?id=4809https://www.debian.org/security/2022/dsa-5229
2022-01-25
Published