PT-2020-21080 · Unknown · Font-Scrubber

Published

2020-09-02

·

Updated

2020-09-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions font-scrubber version 1.2.2
Description The issue concerns malicious code in the postinstall script of the affected software, which attempts to upload sensitive system files to a remote server. These files include configuration files, command history logs, SSH keys, and /etc/passwd.
Recommendations For version 1.2.2, consider the computer fully compromised and remove the package. However, due to potential full control given to an outside entity, removal may not eliminate all malicious software. Rotate all secrets and keys stored on the compromised computer immediately from a different computer.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-65J7-66P7-9XGF

Affected Products

Font-Scrubber