summaryrefslogtreecommitdiffstats
path: root/meta/recipes-support/diffoscope/diffoscope_208.bb
Commit message (Collapse)AuthorAgeFilesLines
* diffoscope: fix CVE-2024-25711Jiaying Song2024-12-091-0/+1
| | | | | | | | | | | | | | | | | | diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted. Reference: https://nvd.nist.gov/vuln/detail/CVE-2024-25711 Upstream patches: https://salsa.debian.org/reproducible-builds/diffoscope/-/commit/458f7f04bc053a0066aa7d2fd3251747d4899476 (From OE-Core rev: da4977e9414361a30eb322d1456a664515b35693) Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
* diffoscope: upgrade 207 -> 208wangmy2022-03-291-0/+30
(From OE-Core rev: 9befbe17c1ff8222c782489cead17e441a927ae1) Signed-off-by: Wang Mingyu <wangmy@fujitsu.com> Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>