CVE-2024-25711
HIGHdiffoscope < 256 - Directory Traversal via GPG Embedded Filename
Title source: llmDescription
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.
References (4)
Core 4
Core References
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/OUNBANAWD6TZH2NRRV4YUIAXEHLUJQ47/
Scores
CVSS v3
7.5
EPSS
0.0526
EPSS Percentile
90.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (3)
fedoraproject/fedora
39
pypi/diffoscope
0 - 256PyPI
reproducible_builds/diffoscope
< 256
Published
Feb 27, 2024
Tracked Since
Feb 18, 2026