Oval Definition:oval:org.opensuse.security:def:202241716
Revision Date:2023-06-22Version:1
Title:CVE-2022-41716
Description:

Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string "A=B\x00C=D" sets the variables "A=B" and "C=D".
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2022-41716
SUSE CVE-2022-41716
SUSE-CU-2022:3024-1
SUSE-CU-2022:3025-1
SUSE-SU-2022:4054-1
SUSE-SU-2022:4055-1
SUSE-SU-2023:2312-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Module for Development Tools 15 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Product(s):
Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Development Tools 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND Package Information
  • go1.19-1.19.9-150000.1.31.1 is installed
  • OR go1.19-doc-1.19.9-150000.1.31.1 is installed
  • OR go1.19-race-1.19.9-150000.1.31.1 is installed
  • BACK