attic before 0.15 does not confirm unencrypted backups with the user, which allows remote attackers with read and write privileges for the encrypted repository to obtain potentially sensitive information by changing the manifest type byte of the repository to "unencrypted / without key file".
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2015/05/31/3 | Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/74821 | Third Party Advisory VDB Entry |
https://github.com/jborg/attic/commit/78f9ad1faba7193ca7f0acccbc13b1ff6ebf9072 | Third Party Advisory |
https://github.com/jborg/attic/issues/271 | Exploit Third Party Advisory |
http://www.openwall.com/lists/oss-security/2015/05/31/3 | Mailing List Third Party Advisory |
http://www.securityfocus.com/bid/74821 | Third Party Advisory VDB Entry |
https://github.com/jborg/attic/commit/78f9ad1faba7193ca7f0acccbc13b1ff6ebf9072 | Third Party Advisory |
https://github.com/jborg/attic/issues/271 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 02:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2015/05/31/3 - Mailing List, Third Party Advisory | |
References | () http://www.securityfocus.com/bid/74821 - Third Party Advisory, VDB Entry | |
References | () https://github.com/jborg/attic/commit/78f9ad1faba7193ca7f0acccbc13b1ff6ebf9072 - Third Party Advisory | |
References | () https://github.com/jborg/attic/issues/271 - Exploit, Third Party Advisory |
Information
Published : 2017-08-18 16:29
Updated : 2024-11-21 02:30
NVD link : CVE-2015-4082
Mitre link : CVE-2015-4082
CVE.ORG link : CVE-2015-4082
JSON object : View
Products Affected
attic_project
- attic
CWE
CWE-264
Permissions, Privileges, and Access Controls