CVE-2017-8296
Last modified
CVE-2017-8296 is a vulnerability of currently unknown severity. kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. EPSS estimates a 1.38% chance of exploitation in the next 30 days.
Description
kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the "password" command is used with an argument. The names of the password entries created and consulted are also accessible in cleartext.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ked Password Manager Project | Ked Password Manager | 0.5 |
| Ked Password Manager Project | Ked Password Manager | 1.0 |
References
- http://openwall.com/lists/oss-security/2017/04/26/9Mailing List, Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860817Issue Tracking, Patch
- https://sourceforge.net/p/kedpm/bugs/6/Issue Tracking, Patch, Third Party Advisory
- http://openwall.com/lists/oss-security/2017/04/26/9Mailing List, Third Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860817Issue Tracking, Patch
- https://sourceforge.net/p/kedpm/bugs/6/Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8296?
How severe is CVE-2017-8296?
How do I fix CVE-2017-8296?
Are you affected by CVE-2017-8296?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
