PT-2024-32672 · Xz Utils · Xz Utils

Splitline

·

Published

2024-10-02

·

Updated

2026-03-29

·

CVE-2024-47611

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions XZ Utils versions 5.6.2 and older
Description The issue concerns a command line argument injection vulnerability in XZ Utils when built for native Windows. This occurs when Unicode characters in filenames are converted to similar-looking ASCII characters, potentially changing the command line's meaning and allowing for argument injection or directory traversal attacks. The estimated number of potentially affected devices is not specified.
Recommendations For versions 5.6.2 and older, update to version 5.6.3 or newer to resolve the issue. As a temporary workaround, consider avoiding the use of Unicode characters in filenames for command line tools until a patch is applied. Restrict access to sensitive directories to minimize the risk of directory traversal attacks.

Exploit

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

CVE-2024-47611
GHSA-M538-C5QW-3CG4

Affected Products

Xz Utils