PT-2024-32672 · Xz Utils · Xz Utils
Splitline
·
Published
2024-10-02
·
Updated
2026-03-29
·
CVE-2024-47611
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
XZ Utils versions 5.6.2 and older
Description
The issue concerns a command line argument injection vulnerability in XZ Utils when built for native Windows. This occurs when Unicode characters in filenames are converted to similar-looking ASCII characters, potentially changing the command line's meaning and allowing for argument injection or directory traversal attacks. The estimated number of potentially affected devices is not specified.
Recommendations
For versions 5.6.2 and older, update to version 5.6.3 or newer to resolve the issue. As a temporary workaround, consider avoiding the use of Unicode characters in filenames for command line tools until a patch is applied. Restrict access to sensitive directories to minimize the risk of directory traversal attacks.
Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xz Utils