Code Injection in USBView - CVE-2022-23220
Published: January 24, 2022
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to improper authentication validation by certain Polkit settings for pkexec. A local user can send a specially crafted request using the --gtk-module option and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Ubuntu
Fedora
usbview (Debian package)
usbview (Ubuntu package)
app-admin/usbview
usbview
How to mitigate CVE-2022-23220
usbview (Debian package) - addressed in versions 2.0-21-g6fe2f4f-2+deb10u1, 2.0-21-g6fe2f4f-2+deb11u1
usbview (Ubuntu package) - addressed in versions 2.0-21-g6fe2f4f-2ubuntu0.20.04.1, 2.0-21-g6fe2f4f-2ubuntu0.21.10.3, 2.0-21-g6fe2f4f-1ubuntu1.1
app-admin/usbview - update to 2.2
usbview - addressed in versions 3.0-1.fc34, 3.0-1.fc35