Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-12356

Опубликовано: 15 июн. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output of GnuPG with an incomplete regular expression, which allows remote attackers to spoof file signatures on configuration files and extension scripts. Modifying the configuration file allows the attacker to inject additional encryption keys under their control, thereby disclosing passwords to the attacker. Modifying the extension scripts allows the attacker arbitrary code execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:simple_password_store_project:simple_password_store:*:*:*:*:*:*:*:*
Версия от 1.7.0 (включая) до 1.7.2 (исключая)

EPSS

Процентиль: 85%
0.02614
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output of GnuPG with an incomplete regular expression, which allows remote attackers to spoof file signatures on configuration files and extension scripts. Modifying the configuration file allows the attacker to inject additional encryption keys under their control, thereby disclosing passwords to the attacker. Modifying the extension scripts allows the attacker arbitrary code execution.

CVSS3: 9.8
debian
больше 7 лет назад

An issue was discovered in password-store.sh in pass in Simple Passwor ...

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output of GnuPG with an incomplete regular expression, which allows remote attackers to spoof file signatures on configuration files and extension scripts. Modifying the configuration file allows the attacker to inject additional encryption keys under their control, thereby disclosing passwords to the attacker. Modifying the extension scripts allows the attacker arbitrary code execution.

EPSS

Процентиль: 85%
0.02614
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-347