Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
diffoscope 安全漏洞
Vulnerability Description
diffoscope是diffoscope开源的一款用于检查文件或目录的异同的工具。 diffoscope 256之前版本存在安全漏洞,该漏洞源于允许通过 GPG 文件中嵌入的文件名进行目录遍历。
CVSS Information
N/A
Vulnerability Type
N/A