CVE-2024-25711

HIGH7.5EPSS 5.3%

diffoscope Path Traversal vulnerability

發布日:2024/2/27修改日:2024/12/5
也稱為:GHSA-33w6-hvmq-gh4xDEBIAN-CVE-2024-25711PYSEC-2024-41

描述

diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

參考連結(8)