[ansible] Command Injection in ansible

Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible …

[diffoscope] Path traversal in diffoscope

diffoscope before 76 writes to arbitrary locations on disk based on the contents of an untrusted archive.
References

https://nvd.nist.gov/vuln/detail/CVE-2017-0359
https://security-tracker.debian.org/tracker/CVE-2017-0359
https://github.com/anthraxx/d…