Spring4Shell Vulnerabilities and GeoExpress
Spring4Shell Vulnerabilities and GeoExpress

Issue
On March 29th, CVE-2022-22963 and CVE-2022-22965 were reported describing an exploit in the Spring4Shell library allowing a malicious user to download the Mirai sample to the “/tmp” folder and execute it after permission change using “chmod”.
Solution
All versions of GeoExpress are NOT affected by the reported vulnerabilities.
Our development teams have reviewed all other vulnerabilities in our Geo products and have determined these all to be low risk to the product. This means an attacker does not have control over what can be modified.
If you have any further questions, please submit a support request, and we'll be happy to assist.
About GeoExpress
GeoExpress is a high-performance geospatial image compression program designed to allow huge raster datasets to be compressed with a minimum loss in quality. Based on the cutting-edge MrSID technology, GeoExpress provides GIS professionals, mapping companies, drone service providers, remote sensing professionals, and government organizations with an effective way to compress, handle, and distribute aerial, satellite, orthophoto, DEM, and scanned images. The advantages of GeoExpress include minimizing the amount of storage space needed to store geospatial images and speeding up their transfer. An extensive range of raster file formats is supported by GeoExpress, and the program integrates seamlessly into other GIS tools, lending itself to enterprise-level management of geospatial data.
GeoExpress

