Reproducible Builds Diffoscope vulnerabilities
2 known vulnerabilities affecting reproducible_builds/diffoscope.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2024-25711HIGHCVSS 7.5fixed in 2562024-02-27
CVE-2024-25711 [HIGH] CWE-22 CVE-2024-25711: diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.
ghsanvdosv
CVE-2017-0359CRITICALCVSS 9.8PoCfixed in 772018-04-13
CVE-2017-0359 [CRITICAL] CVE-2017-0359: diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted arc
diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.
ghsanvdosv