CVE-2018-12356
Last modified
CVE-2018-12356 is a vulnerability of currently unknown severity. An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output of GnuPG with an incomplete regular expression, which allows remote attackers to spoof file signatures on configuration files and extension scripts. EPSS estimates a 4.65% chance of exploitation in the next 30 days.
Description
An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output of GnuPG with an incomplete regular expression, which allows remote attackers to spoof file signatures on configuration files and extension scripts. Modifying the configuration file allows the attacker to inject additional encryption keys under their control, thereby disclosing passwords to the attacker. Modifying the extension scripts allows the attacker arbitrary code execution.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Simple Password Store Project | Simple Password Store | >= 1.7.0, < 1.7.2 |
References
- http://openwall.com/lists/oss-security/2018/06/14/3Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Apr/38Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/30/4Mailing List, Third Party Advisory
- https://git.zx2c4.com/password-store/commit/?id=8683403b77f59c56fcb1f05c61ab33b9fd61a30dPatch, Third Party Advisory
- https://lists.zx2c4.com/pipermail/password-store/2018-June/003308.htmlMailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2018/06/14/3Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Apr/38Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/30/4Mailing List, Third Party Advisory
- https://git.zx2c4.com/password-store/commit/?id=8683403b77f59c56fcb1f05c61ab33b9fd61a30dPatch, Third Party Advisory
- https://lists.zx2c4.com/pipermail/password-store/2018-June/003308.htmlMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12356?
How severe is CVE-2018-12356?
How do I fix CVE-2018-12356?
Are you affected by CVE-2018-12356?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
