CVE-2024-25711: Path Traversal
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/idrsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/diffoscopeto a version that resolves this vulnerability.Fixed in 256
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25711?
CVE-2024-25711 has a medium severity level due to its potential for unauthorized file disclosure.
How do I fix CVE-2024-25711?
You can fix CVE-2024-25711 by upgrading to diffoscope version 256 or later.
What vulnerability does CVE-2024-25711 exploit?
CVE-2024-25711 exploits a directory traversal vulnerability via an embedded filename in a GPG file.
What files can be accessed due to CVE-2024-25711?
CVE-2024-25711 may allow access to sensitive files such as ../.ssh/id_rsa.
Which version of diffoscope is affected by CVE-2024-25711?
Diffoscope versions earlier than 256 are affected by CVE-2024-25711.