QID 997549
Date Published: 2024-02-28
QID 997549: Python (Pip) Security Update for diffoscope (GHSA-33w6-hvmq-gh4x)
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-33w6-hvmq-gh4x for updates and patch information.
Vendor References
- GHSA-33w6-hvmq-gh4x -
github.com/advisories/GHSA-33w6-hvmq-gh4x
CVEs related to QID 997549
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-33w6-hvmq-gh4x | diffoscope |
|