• CVE-2024-47611

发布时间: 2024年11月8日

修改时间: 2024年11月8日

概要

XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command line tools from XZ Utils 5.6.2 and older have a command line argument injection vulnerability. If a command line contains Unicode characters (for example, filenames) that don't exist in the current legacy code page, the characters are converted to similar-looking characters with best-fit mapping. Some best-fit mappings result in ASCII characters that change the meaning of the command line, which can be exploited with malicious filenames to do argument injection or directory traversal attacks. This vulnerability is fixed in 5.6.3. Command line tools built for Cygwin or MSYS2 are unaffected. liblzma is unaffected.

CVSS v3 指标

NVD openEuler
CVSS评分 6.3 5.3
Attack Vector Network Local
Attack Complexity Low Low
Privileges Required None Low
User Interaction None None
Scope Unchanged
Confidentiality Low
Integrity Low
Availability Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-4060 XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command line tools from XZ Utils 5.6.2 and older have a command line argument injection vulnerability. If a command line contains Unicode characters (for example, filenames) that don't exist in the current legacy code page, the characters are converted to similar-looking characters with best-fit mapping. Some best-fit mappings result in ASCII characters that change the meaning of the command line, which can be exploited with malicious filenames to do argument injection or directory traversal attacks. This vulnerability is fixed in 5.6.3. Command line tools built for Cygwin or MSYS2 are unaffected. liblzma is unaffected. 2024年11月8日

影响产品

产品 状态
KY3.4-5A xz Unaffected
KY3.5.2 xz Unaffected
V6 xz Unaffected