PT-2020-21080 · Unknown · Font-Scrubber
Published
2020-09-02
·
Updated
2020-09-02
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
font-scrubber version 1.2.2
Description
The issue concerns malicious code in the postinstall script of the affected software, which attempts to upload sensitive system files to a remote server. These files include configuration files, command history logs, SSH keys, and /etc/passwd.
Recommendations
For version 1.2.2, consider the computer fully compromised and remove the package. However, due to potential full control given to an outside entity, removal may not eliminate all malicious software. Rotate all secrets and keys stored on the compromised computer immediately from a different computer.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Font-Scrubber