UBUNTU-CVE-2024-25711

Source
https://ubuntu.com/security/CVE-2024-25711
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-25711.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2024-25711
Related
Published
2024-02-27T02:15:00Z
Modified
2024-10-15T14:12:54Z
Summary
[none]
Details

diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.

References

Affected packages

Ubuntu:Pro:16.04:LTS / diffoscope

Package

Name
diffoscope
Purl
pkg:deb/ubuntu/diffoscope?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other

33
38
41
42
48
49
51

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / diffoscope

Package

Name
diffoscope
Purl
pkg:deb/ubuntu/diffoscope?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other

87
88
90build1
91build1
91ubuntu1
92ubuntu1
93ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / diffoscope

Package

Name
diffoscope
Purl
pkg:deb/ubuntu/diffoscope?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other

125
131
132
133
134
135
136
137

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / diffoscope

Package

Name
diffoscope
Purl
pkg:deb/ubuntu/diffoscope?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other

180
194build
195
200
201
202
203
204
205

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / diffoscope

Package

Name
diffoscope
Purl
pkg:deb/ubuntu/diffoscope?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
259

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "259",
            "binary_name": "diffoscope"
        },
        {
            "binary_version": "259",
            "binary_name": "diffoscope-minimal"
        }
    ]
}

Ubuntu:24.04:LTS / diffoscope

Package

Name
diffoscope
Purl
pkg:deb/ubuntu/diffoscope?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other

249
251
253
254
255
257
258
259

Ecosystem specific

{
    "ubuntu_priority": "medium"
}