ASA-2019-00580 – NSA Ghidra: Uncontrolled Search Path Element when executing CMD


Allele Security Alert

ASA-2019-00580

Identifier(s)

ASA-2019-00580, CVE-2019-17664

Title

Uncontrolled Search Path Element when executing CMD

Vendor(s)

National Security Agency (NSA)

Product(s)

NSA Ghidra

Affected version(s)

NSA Ghidra versions up to and including 9.1

Fixed version(s)

Unknown

Proof of concept

Unknown

Description

When executing Ghidra from a given path, the Java process working directory is set to this path. Then, when launching the Python interpreter via the “Ghidra Codebrowser > Window > Python” option, Ghidra will try to execute the cmd.exe program from this working directory.

Technical details

Unknown

Credits

dalvarezperez

Reference(s)

Uncontrolled Search Path Element when executing CMD. #107
https://github.com/NationalSecurityAgency/ghidra/issues/107

CVE-2019-17664
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17664

CVE-2019-17664
https://nvd.nist.gov/vuln/detail/CVE-2019-17664

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: October 21, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.