kedpm における情報漏えいに関する脆弱性
| Title |
kedpm における情報漏えいに関する脆弱性
|
| Summary |
kedpm には、情報漏えいに関する脆弱性が存在します。
|
| Possible impacts |
情報を取得される可能性があります。 |
| Solution |
ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date |
April 19, 2017, midnight |
| Registration Date |
June 2, 2017, 4:49 p.m. |
| Last Update |
June 2, 2017, 4:49 p.m. |
|
CVSS3.0 : 重要
|
| Score |
7.5
|
| Vector |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
|
CVSS2.0 : 警告
|
| Score |
5
|
| Vector |
AV:N/AC:L/Au:N/C:P/I:N/A:N |
Affected System
| Ked Password Manager project |
|
kedpm 0.5
|
|
kedpm 1.0
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
その他
Change Log
| No |
Changed Details |
Date of change |
| 0 |
[2017年06月02日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
NVD Vulnerability Information
CVE-2017-8296
| Summary |
kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the "password" command is used with an argument. The names of the password entries created and consulted are also accessible in cleartext.
|
| Publication Date |
April 28, 2017, 12:59 a.m. |
| Registration Date |
Jan. 26, 2021, 1:29 p.m. |
| Last Update |
Nov. 21, 2024, 12:33 p.m. |
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:ked_password_manager_project:ked_password_manager:0.5:*:*:*:*:*:*:* |
|
|
|
|
| cpe:2.3:a:ked_password_manager_project:ked_password_manager:1.0:*:*:*:*:*:*:* |
|
|
|
|
Related information, measures and tools
Common Vulnerabilities List