ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working directory via the -z/–search-zip or –pre flag.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ripgrep | Ripgrep_project | * | 13.0.0 (excluding) |
Ripgrep | Ubuntu | trusty | * |
Ripgrep | Ubuntu | upstream | * |
Ripgrep | Ubuntu | xenial | * |
Rust-ripgrep | Ubuntu | kinetic | * |
Rust-ripgrep | Ubuntu | trusty | * |
Rust-ripgrep | Ubuntu | upstream | * |
Rust-ripgrep | Ubuntu | xenial | * |