GHSA-8p5c-f328-9fvv

Suggest an improvement
Source
https://github.com/advisories/GHSA-8p5c-f328-9fvv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-8p5c-f328-9fvv/GHSA-8p5c-f328-9fvv.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-8p5c-f328-9fvv
Aliases
Published
2018-07-13T16:01:21Z
Modified
2025-02-15T05:30:03.543070Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Diffoscope may write to arbitrary locations due to an untrusted archive
Details

diffoscope before 76 writes to arbitrary locations on disk based on the contents of an untrusted archive.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-22"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:26:06Z"
}
References

Affected packages

PyPI / diffoscope

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
76

Affected versions

Other

39
40
41
42
43
44
45
46
47
48
49
51
52
54
55
56
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75