CVE-2024-56334

unknown
Published 2024-12-20 Β· Modified 2024-12-20
CVSS v3
β€”
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
β€”

Description

systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter to cmd.exe in the `getWindowsIEEE8021x` function. This means that malicious content in the SSID can be executed as OS commands. This vulnerability may enable an attacker, depending on how the package is used, to perform remote code execution or local privilege escalation. This issue has been addressed in version 5.23.7 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2024-56334 NameCVE-2024-56334 Descriptionsysteminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter to cmd.exe in the `getWindowsIEEE8021x` function. This means that malicious content in the SSID can be executed as OS commands. This vulnerability may enable an attacker, depending on how the…

Workaround

s for this vulnerability. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus jupyterlab (PTS)trixie4.0.11+ds1+~cs11.25.27-7vulnerable forky4.0.11+ds5+~cs11.25.27-1fixed sid4.0.13+ds1+~2.0.1+~cs1.4.4-1fixed node-systeminformation (PTS)forky5.31.6-4fixed sid5.31.7-1fixed The information below is based on the following data on fixed versions. PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs jupyterlabsource(unstable)4.0.11+ds5+~cs11.25.27-1 node-systeminformationsource(unstable)(not affected) Notes - node-systeminformation <not-affected> (Fixed before initial upload to Debian) node-systeminformation splited from jupyterlab

CVE-2024-56334

NameCVE-2024-56334
Descriptionsysteminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter to cmd.exe in the `getWindowsIEEE8021x` function. This means that malicious content in the SSID can be executed as OS commands. This vulnerability may enable an attacker, depending on how the package is used, to perform remote code execution or local privilege escalation. This issue has been addressed in version 5.23.7 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
jupyterlab (PTS)trixie4.0.11+ds1+~cs11.25.27-7vulnerable
forky4.0.11+ds5+~cs11.25.27-1fixed
sid4.0.13+ds1+~2.0.1+~cs1.4.4-1fixed
node-systeminformation (PTS)forky5.31.6-4fixed
sid5.31.7-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
jupyterlabsource(unstable)4.0.11+ds5+~cs11.25.27-1
node-systeminformationsource(unstable)(not affected)

Notes

- node-systeminformation <not-affected> (Fixed before initial upload to Debian)
node-systeminformation splited from jupyterlab

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
- node-systeminformation <not-affected> (Fixed before initial upload to Debian)node-systeminformation splited from jupyterlab

OS impact

debian Debian Mixed 3 releases
VersionStatusFixed in
trixie Affected β€”
sid Fixed 0
forky Fixed 0

Package impact

EcosystemPackageVulnerableFixed
npm npmsysteminformation<5.23.75.23.7

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.