PT-2022-21702 · Diffy · Diffy

Tehryanx

·

Published

2022-06-22

·

Updated

2022-06-29

·

CVE-2022-33127

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Diffy versions prior to 3.4.1 Diffy version 3.4.1
Description The function that calls the diff tool in Diffy does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string.
Recommendations For Diffy versions prior to 3.4.1, update to version 3.4.1 or later to resolve the issue. For Diffy version 3.4.1, consider disabling the function that calls the diff tool until a patch is available. Restrict access to the diff tool to minimize the risk of exploitation. Avoid using double quotes in filenames when running Diffy in a Windows environment until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-33127
GHSA-5WW9-9QP2-X524

Affected Products

Diffy