Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

CentOS 8: 2021-72dfc37d5a Severe: Ansible Code Injection

fedora
Calendar Grey February 22, 2017
Scroller Fedora
The recent Fedora 24 upgrade for diffoscope addresses a critical vulnerability that allowed unauthorized write privileges via unverified archive files.
Update to the latest version, fixes a security issue.

Summary

diffoscope will try to get to the bottom of what makes files or directories

different. It will recursively unpack archives of many kinds and transform

various binary formats into more human readable form to compare them. It can

compare two tarballs, ISO images, or PDF just as easily. The differences can

be shown in a text or HTML report.

diffoscope is developed as part of the "reproducible builds" Debian project and

was formerly known as "debbindiff".

Update Information:

Update to the latest version, fixes a security issue.

Change Log

References


[ 1 ] Bug #1421774 - CVE-2017-0359 diffoscope: writes to arbitrary locations on disk based on the contents of an untrusted archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1421774

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade diffoscope' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
important
Lowest
Low
Medium
High
Critical

Name: diffoscope
Product: Fedora 24
Version: 77
Release: 1.fc24
Summary: In-depth comparison of files, archives, and directories

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.