Diffoscope may write to arbitrary locations due to an untrusted archive
Critical severity
GitHub Reviewed
Published
Jul 13, 2018
to the GitHub Advisory Database
•
Updated Sep 16, 2024
Description
Published to the GitHub Advisory Database
Jul 13, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 16, 2024
diffoscope before 76 writes to arbitrary locations on disk based on the contents of an untrusted archive.
References