PT-2018-11141 · Simple Password Store+1 · Pass+1

Marcus Brinkmann

·

Published

2018-06-15

·

Updated

2021-07-03

·

CVE-2018-12356

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pass versions 1.7.x through 1.7.1
Description An issue in the password-store.sh script of Simple Password Store allows remote attackers to spoof file signatures on configuration files and extension scripts due to an incomplete regular expression in the signature verification routine. This can lead to the disclosure of passwords if an attacker modifies the configuration file to inject additional encryption keys. Furthermore, modifying the extension scripts can allow the attacker to execute arbitrary code.
Recommendations For pass versions 1.7.x through 1.7.1, update to version 1.7.2 or later to resolve the issue.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2135
CVE-2018-12356
OPENSUSE-SU-2024:11150-1

Affected Products

Alt Linux
Pass