CVE Feed

    Dashboard / CVE / CVE-2019-13623

    CVE-2019-13623

    In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows attackers to overwrite arbitrary files in scenarios where an intermediate analysis result is archived for sharing with other persons. To achieve arbitrary code execution, one approach is to overwrite some critical Ghidra modules, e.g., the decompile module.

    Published:Jul 17, 2019
    Last Modified:Nov 21, 2024
    EPS:Jul 17, 2019
    EPSS Score:0.04099
    CVSS Score:7.8

    Affected Products

    Vendor
    Nsa
    Product
    Ghidra

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High