vendor:
Ghidra
by:
Etienne Lacoche
7.8
CVSS
HIGH
Command Injection
78
CWE
Product Name: Ghidra
Affected Version From: Ghidra Linux version <= 9.0.4
Affected Version To: Ghidra Linux version <= 9.0.4
Patch Exists: YES
Related CWE: CVE-2019-13623
CPE: a:ghidra:ghidra
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2019
Ghidra-Exploit
This exploit allows an attacker to inject arbitrary commands into Ghidra Linux version <= 9.0.4. The exploit is achieved by creating a malicious .gar file which contains a malicious decompile file. The malicious decompile file contains a command injection payload which is executed when the .gar file is opened in Ghidra. The malicious payload is used to open a reverse shell to the attacker's machine.
Mitigation:
Upgrade to Ghidra version 9.0.4 or later.