Input validation error in Debian Linux - CVE-2017-0359
Published: April 13, 2018 / Updated: August 8, 2020
Vulnerability identifier: #VU37191
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-0359
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.
Affected software
Debian Linux
Arch Linux
Fedora
diffoscope
Arch Linux
Fedora
diffoscope
How to mitigate CVE-2017-0359
Install update from vendor's website.
diffoscope - addressed in versions 77-1.fc24, 77-1.fc25