CVE-2024-25711

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
27/02/2024
Last modified:
04/11/2025

Description

diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:reproducible_builds:diffoscope:*:*:*:*:*:*:*:* 256 (excluding)
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*