Name | CVE-2024-25711 |
Description | diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
diffoscope (PTS) | bullseye | 177 | vulnerable |
| bookworm | 240 | vulnerable |
| sid, trixie | 277 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
diffoscope | source | (unstable) | 256 | | | |
Notes
[bookworm] - diffoscope <no-dsa> (Minor issue)
[bullseye] - diffoscope <no-dsa> (Minor issue)
[buster] - diffoscope <no-dsa> (Minor issue; fix it along the next DLA)
https://salsa.debian.org/reproducible-builds/diffoscope/-/issues/361
https://salsa.debian.org/reproducible-builds/diffoscope/-/commit/458f7f04bc053a0066aa7d2fd3251747d4899476 (256)