Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7796-9c37-q364

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key.

ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key.

EPSS

Процентиль: 42%
0.00197
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 5 лет назад

ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key.

CVSS3: 9.8
nvd
около 5 лет назад

ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key.

CVSS3: 9.8
debian
около 5 лет назад

ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-c ...

EPSS

Процентиль: 42%
0.00197
Низкий

Дефекты

CWE-287