Logo
componentdiffoscope
Name
diffoscope
Version
208
Type
library
Description
in-depth comparison of files, archives, and directories
Licenses
GPL-3.0-or-later
PURL
-
CPE
cpe:2.3:*:*:diffoscope:208:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
319
scarthgap
259

Patches#


#
Title
Author
Resolve
1
Use a determistic name instead of trusting gpg's
Chris Lamb <lamby@debian.org>
CVE-2024-25711

Vulnerabilities#


Name
Analysis
Description
Patched
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.