GHSA-8p5c-f328-9fvv
Dashboard / Vulnerabilities / GHSA-8p5c-f328-9fvv
GHSA-8p5c-f328-9fvv
Summary: Diffoscope may write to arbitrary locations due to an untrusted archive
Details: diffoscope before 76 writes to arbitrary locations on disk based on the contents of an untrusted archive.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-0359, https://github.com/anthraxx/diffoscope/commit/632a40828a54b399787c25e7fa243f732aef7e05, https://github.com/anthraxx/diffoscope/commit/f379d1f611dbd5d361e12b732e07c8aee45ff226, https://bugs.debian.org/854723, https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854723, https://github.com/advisories/GHSA-8p5c-f328-9fvv, https://github.com/anthraxx/diffoscope, https://github.com/pypa/advisory-database/tree/main/vulns/diffoscope/PYSEC-2018-83.yaml, https://security-tracker.debian.org/tracker/CVE-2017-0359
Affected packages
Package
Name: diffoscope
Purl: pkg:pypi/diffoscope
Affected ranges
Type: ECOSYSTEM
Events:
