← Back

Reproducible Builds

reproducible_builds

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Diffoscope
diffoscope

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Reproducible Builds
2Diffoscope
Fedora
Jun 17, 2026
Feb 27, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embed...Show more
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.Show less
2Debian
Reproducible Builds
2Debian Linux
Diffoscope
Nov 21, 2024
Apr 13, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.