Reproducible Builds

Diffoscope

2 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.16%
  • Published 27.02.2024 02:15:06
  • Last modified 28.05.2025 16:15:32

diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is truste...

Exploit
  • EPSS 0.54%
  • Published 13.04.2018 16:29:00
  • Last modified 21.11.2024 03:02:49

diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.