1 Tag Serie
📰 IT Security Nachrichten 🕛 vor 9 Jahren 1 Min Lesezeit SECURITY-FEED
0

Cryptkeeper Linux Encryption App Fails at Job, Has One Letter Skeleton Key - "P"

↗ Quelle (news.softpedia.com)
🗣️ Stimme:
Cryptkeeper, famous Linux encryption app, is not as safe as one would like since a bug has been discovered, allowing universal decryption with a single letter: “p.”

The flawed version can be found in Debian 9 (Stretch), which is currently in testing, but not in Debian 8 (Jessie). According to the folks who discovered the bug, it seems that this is a result of Cryptkeeper invoking encfs and attempting to enter paranoia mode. It does this with a simulated “p” keypress but instead of doing that it sets the folder password to this particular letter.

Considering this is a tool that’s supposed to offer people protection by encrypting their files, it’s quite ironic that it could be opened universally with a single letter.

The problem seems to stem from the fact that encfs is executed with –S switch, reading the password from stdin without a particular prompt.  Following an encfs bug that prevented it from doing what it was supposed to do, a bugfix was released to correc...
Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf news.softpedia.com.
↗ Original-Artikel auf news.softpedia.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
9 Quellen
CVE-2022-44169 | Tenda AC15 15.03.05.18 formSetVirtualSer buffer overflow (EUVD-2022-47119)
1 Quelle
Best early October Prime Day deals: Save on TVs, smartwatches, and more tech
1 Quelle
I gave Claude Code $100 and 30 days to make a profit. Day 1, it built a product. Here's the pattern it used.