CRITICAL · 9.8

CVE-2017-0359

diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.

Vulnerability Description

diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Reproducible BuildsDiffoscope< 77
DebianDebian Linux9.0

References

FAQ

What is CVE-2017-0359?

CVE-2017-0359 is a vulnerability with a CVSS score of 9.8 (CRITICAL). diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.

How severe is CVE-2017-0359?

CVE-2017-0359 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-0359?

Check the references section above for vendor advisories and patch information. Affected products include: Reproducible Builds Diffoscope, Debian Debian Linux.