Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-28638

Опубликовано: 13 нояб. 2020
Источник: debian
EPSS Низкий

Описание

ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tombfixed2.8+dfsg1-1package
tombnot-affectedbusterpackage

Примечания

  • https://github.com/dyne/Tomb/issues/385

  • Introduced by: https://github.com/dyne/Tomb/commit/477ab204439ddb88d7293d3c35a29e29751feda9 (v2.6)

  • https://github.com/dyne/Tomb/pull/386

  • Attempted to be fixed via: https://github.com/dyne/Tomb/commit/15c894dfb41db3ea3290bdf8f958fd9e3503c4bb

  • which only hides the problem.

  • https://github.com/dyne/Tomb/issues/392

EPSS

Процентиль: 42%
0.00197
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 5 лет назад

ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key.

CVSS3: 9.8
nvd
около 5 лет назад

ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key.

github
больше 3 лет назад

ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key.

EPSS

Процентиль: 42%
0.00197
Низкий