CVE-2015-4082
Summary
| CVE | CVE-2015-4082 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-18 16:29:00 UTC |
| Updated | 2017-08-25 12:05:00 UTC |
| Description | attic before 0.15 does not confirm unencrypted backups with the user, which allows remote attackers with read and write privileges for the encrypted repository to obtain potentially sensitive information by changing the manifest type byte of the repository to "unencrypted / without key file". |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Attic Project | Attic | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security bug: decryption attack · Issue #271 · jborg/attic · GitHub | CONFIRM | github.com | Exploit, Third Party Advisory |
| Attic 'attic/archiver.py' Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| oss-security - Re: CVE request for attic : encrypted backups attack | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| Require approval before accessing previously unknown unencrypted repo… · jborg/attic@78f9ad1 · GitHub | CONFIRM | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.