Logo
vulnerabilityCVE-2024-25711
Name
CVE-2024-25711
Source
NVD ( link)Debian ( link)
Description
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
diffoscope
Patched

Vulnerability Ratings#


7.5
CVSSv31
7.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
319
Not Affected
yocto
scarthgap
259
Not Affected

Resolved with patches#


diffoscope (yocto:kirkstone)

#
Title
Author
Resolve
1
Use a determistic name instead of trusting gpg's
Chris Lamb <lamby@debian.org>
CVE-2024-25711