CVE Vulnerabilities

CVE-2020-28638

Improper Authentication

Published: Nov 13, 2020 | Modified: Dec 02, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users files to be encrypted with tomb {W] Detected DISPLAY, but only pinentry-curses is found. as the encryption key.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Tomb Dyne 2.0 (including) 2.7 (including)
Tomb Ubuntu bionic *
Tomb Ubuntu groovy *
Tomb Ubuntu trusty *
Tomb Ubuntu upstream *

Potential Mitigations

References