{"id":"CVE-2025-59534","summary":"CryptoLib command Injection vulnerability in initialize_kerberos_keytab_file_login()","details":"CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.2, there is a command Injection vulnerability in initialize_kerberos_keytab_file_login(). The vulnerability exists because the code directly interpolates user-controlled input into a shell command and executes it via system() without any sanitization or validation. This issue has been patched in version 1.4.2.","aliases":["GHSA-jw5c-58hr-m3v3"],"modified":"2026-08-12T15:13:33.361011Z","published":"2025-09-23T18:25:06.128Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59534.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-78"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59534.json"},{"type":"ADVISORY","url":"https://github.com/nasa/CryptoLib/security/advisories/GHSA-jw5c-58hr-m3v3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59534"},{"type":"FIX","url":"https://github.com/nasa/CryptoLib/commit/3ccb1b306026bb20a028fbfdcf18935f7345ed2f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nasa/cryptolib","events":[{"introduced":"0"},{"fixed":"309c1c4a57313044215ca730abfa3fbe9e5feed0"},{"fixed":"3ccb1b306026bb20a028fbfdcf18935f7345ed2f"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.4.2"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:nasa:cryptolib:*:*:*:*:*:*:*:*"}}],"versions":["v1.4.0","v1.3.3","v1.3.2","v1.3.1","v1.3.0","v1.2.3","v1.2.2","v1.2.1","v1.2.0","v1.1.1","v1.1.0","v1.0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59534.json","vanir_signatures_modified":"2026-08-12T15:13:33Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"82167588740341724689229803591942942757","length":1163},"id":"CVE-2025-59534-212e9ac3","signature_type":"Function","signature_version":"v1","source":"https://github.com/nasa/cryptolib/commit/3ccb1b306026bb20a028fbfdcf18935f7345ed2f","target":{"file":"src/core/crypto_config.c","function":"Crypto_Config_Cam"}},{"deprecated":false,"digest":{"line_hashes":["19223788069184401538722344807199118592","104181030498499483131937906529158747539","253138828997757988604524689403090078255","255278390759545512452914727701349652364"],"threshold":0.9},"id":"CVE-2025-59534-47d09363","signature_type":"Line","signature_version":"v1","source":"https://github.com/nasa/cryptolib/commit/3ccb1b306026bb20a028fbfdcf18935f7345ed2f","target":{"file":"src/core/crypto_config.c"}},{"signature_version":"v1","source":"https://github.com/nasa/cryptolib/commit/3ccb1b306026bb20a028fbfdcf18935f7345ed2f","target":{"file":"include/crypto.h"},"deprecated":false,"digest":{"line_hashes":["290675830297355724961563646952268716264","202699612594371479224974327021384681202","291309237428317339859623483181338001472","257386750406983993619937544944754691981","310545720560411361427048788897032568333","278121097331583484573585504001334060991","50575670193926920763147319589024248722"],"threshold":0.9},"id":"CVE-2025-59534-618dab0e","signature_type":"Line"},{"id":"CVE-2025-59534-cfe53444","signature_type":"Line","signature_version":"v1","source":"https://github.com/nasa/cryptolib/commit/3ccb1b306026bb20a028fbfdcf18935f7345ed2f","target":{"file":"src/crypto/kmc/cryptography_interface_kmc_crypto_service.template.c"},"deprecated":false,"digest":{"line_hashes":["104980725956018480940042628546137937822","308115673510451441088209925017483099293","279734690743554434475713639210413031678","127163144964513772717334775941636792509","173740761547730600387411217850457428627","254535996999665213041349732626957750519","22652593665051045843424297733578698938","268591892119410890984414815052766786278","51648192281868503968607972731452512280","176250249248463142566701849531676856124","59456138023034190172281872528932466914","255865496792885289554610245265279298630","56387618883527959139165947445796595726","169829273634023480458501749098321366581","12113653957629061757373117116881105295","21884963974220998548870698565185764047","244651769212558715173160651715735127932","200201039847907677242776455446565649344","200074372288164687920361056048391038429","186843798853123471171194138475754359454","59008687812215540647691668727092358786","277143963295783113051258681374575062361","111334699951513043699683582286087116152","170537918468641179415615000007365215610","184209652204005977149834549064804202010"],"threshold":0.9}},{"target":{"file":"src/crypto/kmc/cryptography_interface_kmc_crypto_service.template.c","function":"initialize_kerberos_keytab_file_login"},"deprecated":false,"digest":{"function_hash":"234982026387131909918091953083921726871","length":772},"id":"CVE-2025-59534-d418f8fb","signature_type":"Function","signature_version":"v1","source":"https://github.com/nasa/cryptolib/commit/3ccb1b306026bb20a028fbfdcf18935f7345ed2f"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}