Code Injection in USBView - CVE-2022-23220

 

Code Injection in USBView - CVE-2022-23220

Published: January 24, 2022


Vulnerability identifier: #VU59950
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23220
CWE-ID: CWE-94
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to improper authentication validation by certain Polkit settings for pkexec. A local user can send a specially crafted request using the --gtk-module option and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

USBView
Gentoo Linux
Ubuntu
Fedora
usbview (Debian package)
usbview (Ubuntu package)
app-admin/usbview
usbview

How to mitigate CVE-2022-23220

Install updates from vendor's website.

USBView - update to 2.2
usbview (Debian package) - addressed in versions 2.0-21-g6fe2f4f-2+deb10u1, 2.0-21-g6fe2f4f-2+deb11u1
usbview (Ubuntu package) - addressed in versions 2.0-21-g6fe2f4f-2ubuntu0.20.04.1, 2.0-21-g6fe2f4f-2ubuntu0.21.10.3, 2.0-21-g6fe2f4f-1ubuntu1.1
app-admin/usbview - update to 2.2
usbview - addressed in versions 3.0-1.fc34, 3.0-1.fc35

External References

Related Security Bulletins