CVE-2019-14422 Vulnerability

27 views
Skip to first unread message

F&F Technologies

unread,
Mar 22, 2023, 10:53:04 AM3/22/23
to TortoiseSVN-dev
Good day all.

My organization is trying to use TortoiseSVN as a version control client. In researching, from the user group, it looks as though this may not be accepted as a vulnerability by TortoiseSVN.

The concern is that a macro can be executed which might harm a network. It appears that there are a number of steps to get there.

1. Can someone please advise if this was addressed?

2. If addressed, where might I find documentation on the resolution?

3. If not are there plans to?

4. If no plans requesting explanation why so I can present to organization.

I am hoping to obtain answer by end of day Thursday as I have a meeting to rebut objections.

Thanks.

Daniel Sahlberg

unread,
Mar 22, 2023, 12:10:20 PM3/22/23
to TortoiseSVN-dev
Please check r28647 of the diff script at https://svn.osdn.net/svnroot/tortoisesvn/trunk/contrib/diff-scripts/, it adds a protection layer by disabling macros:

// disable all macros
objExcelApp.AutomationSecurity = 3; //msoAutomationSecurityForceDisable

Based on the date it seems to be in reaction to the CVE. It should have been included in the 1.13 release, it certainly is included as installed in 1.14.5.

Kind regards,
Daniel
 

F&F Technologies

unread,
Mar 22, 2023, 4:39:57 PM3/22/23
to TortoiseSVN-dev
Daniel.

Thank you for the quick response. This definitely helps us to counter the opposition. The objection was a reaction to the CVE being there. The team asking for the software figured there was a fix as it was reported version 1.12.

CA
Reply all
Reply to author
Forward
0 new messages