Описание
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.
Ссылки
- Mailing List
- Patch
- Vendor Advisory
- Mailing List
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 256 (исключая)
cpe:2.3:a:reproducible_builds:diffoscope:*:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.04082
Низкий
7.5 High
CVSS3
7.1 High
CVSS3
Дефекты
CWE-22
CWE-22
Связанные уязвимости
CVSS3: 7.5
ubuntu
почти 2 года назад
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.
CVSS3: 7.5
debian
почти 2 года назад
diffoscope before 256 allows directory traversal via an embedded filen ...
EPSS
Процентиль: 88%
0.04082
Низкий
7.5 High
CVSS3
7.1 High
CVSS3
Дефекты
CWE-22
CWE-22