Loading vulnerability details...
rpassword maintainers were made aware of a possible issue with a partial password reveal when input is interrupted.
To quote @squell:
@conradkleinespel I've confirmed this problem with SequoiaPGP, which I think uses rpassword, e.g.:
Suppose we use pkill -9 sq in a different terminal right after the password has been typed in:
$ sq key generate --userid "barf" --with-password Enter password to protect the key: Killed $ hello^C
Where the password I typed in is "hello".
This has been fixed in version v7.5.0 and above.
rpassword maintainers were made aware of a possible issue with a partial password reveal when input is interrupted.
To quote @squell:
@conradkleinespel I've confirmed this problem with SequoiaPGP, which I think uses rpassword, e.g.:
Suppose we use pkill -9 sq in a different terminal right after the password has been typed in:
$ sq key generate --userid "barf" --with-password Enter password to protect the key: Killed $ hello^C
Where the password I typed in is "hello".
This has been fixed in version v7.5.0 and above.
This high-severity vulnerability could allow attackers to gain unauthorized access, execute arbitrary code, or compromise data integrity. Prompt remediation is strongly recommended.
Apply security patches to version 7.5.0 immediately
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior