diffoscope@220 vulnerabilities

in-depth comparison of files, archives, and directories

  • latest version

    284

  • latest non vulnerable version

  • first published

    9 years ago

  • latest version published

    1 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the diffoscope package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Directory Traversal

    diffoscope is a tool to get to the bottom of what makes files or directories different.

    Affected versions of this package are vulnerable to Directory Traversal due to the improper handling of embedded filenames in GPG files. An attacker can disclose the contents of any file on the system, such as sensitive SSH private keys, by crafting a GPG file that specifies a path traversal in the embedded filename. This vulnerability leverages the --use-embedded-filenames option of GPG, which is incorrectly trusted to specify safe file paths.

    How to fix Directory Traversal?

    Upgrade diffoscope to version 256 or higher.

    [,256)