PT-2018-11141 · Simple Password Store+1 · Pass+1
Marcus Brinkmann
·
Published
2018-06-15
·
Updated
2021-07-03
·
CVE-2018-12356
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pass versions 1.7.x through 1.7.1
Description
An issue in the password-store.sh script of Simple Password Store allows remote attackers to spoof file signatures on configuration files and extension scripts due to an incomplete regular expression in the signature verification routine. This can lead to the disclosure of passwords if an attacker modifies the configuration file to inject additional encryption keys. Furthermore, modifying the extension scripts can allow the attacker to execute arbitrary code.
Recommendations
For pass versions 1.7.x through 1.7.1, update to version 1.7.2 or later to resolve the issue.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Pass