Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-m8r5-7wf4-63mw: Nadesiko3 OS Command Injection vulnerability

OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.68 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product.

Release notes for versions 3.3.62 and 3.3.69 both link to patches for this particular issue. The JPCERT/CC advisory lists versions 3.3.68 and prior as vulnerable, and the most recent patch for this issue is tagged with version 3.3.69.

ghsa
#vulnerability#git

Nadesiko3 OS Command Injection vulnerability

Critical severity GitHub Reviewed Published Dec 5, 2022 • Updated Dec 6, 2022

Related news

CVE-2022-42496: JVN#56968681: Multiple vulnerabilities in nadesiko3

OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product and execute an arbitrary OS command on the product.