Bug 2225206 (CVE-2022-25834) - CVE-2022-25834 percona-xtrabackup: arbitrary shell execution via crafted filename
Summary: CVE-2022-25834 percona-xtrabackup: arbitrary shell execution via crafted file...
Keywords:
Status: NEW
Alias: CVE-2022-25834
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2225207
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-07-24 14:44 UTC by Marian Rehak
Modified: 2023-07-24 14:44 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2023-07-24 14:44:44 UTC
In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected command shell execution of arbitrary commands.

Reference:

https://docs.percona.com/percona-xtrabackup/8.0/release-notes/8.0/8.0.32-26.0.html#improvements
https://www.percona.com/doc/percona-xtrabackup/2.4/index.html

Comment 1 Marian Rehak 2023-07-24 14:44:57 UTC
Created percona-xtrabackup tracking bugs for this issue:

Affects: fedora-37 [bug 2225207]


Note You need to log in before you can comment on or make changes to this bug.