VDB
Sign up
—

PYSEC-2024-41

Quick fix

PYSEC-2024-41 — diffoscope: upgrade to the fixed version with the command below.

pip install --upgrade 'diffoscope>=256'

Details

diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/diffoscope
Introduced in: 0Fixed in: 256
Fixpip install --upgrade 'diffoscope>=256'

References