CVE-2017-8296
Last modified
CVE-2017-8296 is a vulnerability of currently unknown severity. kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. EPSS estimates a 1.38% chance of exploitation in the next 30 days.
Description
kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the "password" command is used with an argument. The names of the password entries created and consulted are also accessible in cleartext.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ked Password Manager Project | Ked Password Manager | 0.5 |
| Ked Password Manager Project | Ked Password Manager | 1.0 |
References
- http://openwall.com/lists/oss-security/2017/04/26/9Mailing List, Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860817Issue Tracking, Patch
- https://sourceforge.net/p/kedpm/bugs/6/Issue Tracking, Patch, Third Party Advisory
- http://openwall.com/lists/oss-security/2017/04/26/9Mailing List, Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860817Issue Tracking, Patch
- https://sourceforge.net/p/kedpm/bugs/6/Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8296?
How severe is CVE-2017-8296?
How do I fix CVE-2017-8296?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-8288gnome-shell 3.22 through 3.24.1 mishandles extensions that f…
- CVE-2017-8289Stack-based buffer overflow in the ipv6_addr_from_str functi…
- CVE-2017-8290A potential Buffer Overflow Vulnerability (from a BB Code ha…
- CVE-2017-8291Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass…7.8
- CVE-2017-8294libyara/re.c in the regex component in YARA 3.5.0 allows rem…
- CVE-2017-8295WordPress through 4.7.4 relies on the Host HTTP header for a…
- CVE-2017-8297A path traversal vulnerability exists in simple-file-manager…
- CVE-2017-8298cnvs.io Canvas 3.3.0 has XSS in the title and content fields…
- CVE-2017-8301LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification i…
- CVE-2017-8302Mura CMS 7.0.6967 allows admin/?muraAction= XSS attacks, rel…
- CVE-2017-8303An issue was discovered on Accellion FTA devices before FTA_…9.8
- CVE-2017-8304An issue was discovered on Accellion FTA devices before FTA_…
Are you affected by CVE-2017-8296?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
