Input validation error in Debian Linux - CVE-2017-0359

 

Input validation error in Debian Linux - CVE-2017-0359

Published: April 13, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37191
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-0359
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.


Affected software

Debian Linux
Arch Linux
Fedora
diffoscope

How to mitigate CVE-2017-0359

Install update from vendor's website.

diffoscope - addressed in versions 77-1.fc24, 77-1.fc25

External References

Related Security Bulletins