CVE-2018-12556
Summary
| CVE | CVE-2018-12556 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-16 17:29:00 UTC |
| Updated | 2019-05-21 14:03:00 UTC |
| Description | The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature to the yarn release key, which allows remote attackers to sign tampered yarn release packages with their own key. |
Risk And Classification
Problem Types: CWE-347
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Johnny-You-Are-Fired/johnny-fired.pdf at master · RUB-NDS/Johnny-You-Are-Fired · GitHub | MISC | github.com | Third Party Advisory |
| GitHub - RUB-NDS/Johnny-You-Are-Fired: Artifacts for the USENIX publication. | MISC | github.com | Third Party Advisory |
| Johnny You Are Fired ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| Commits · yarnpkg/website · GitHub | MISC | github.com | Third Party Advisory |
| Full Disclosure: OpenPGP and S/MIME signature forgery attacks in multiple email clients | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| oss-security - Spoofing OpenPGP and S/MIME Signatures in Emails (multiple clients) | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.