Description
ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-21036 | ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key. |
References
| Link | Providers |
|---|---|
| https://github.com/dyne/Tomb/issues/385 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:40:59.786Z
Reserved: 2020-11-13T00:00:00.000Z
Link: CVE-2020-28638
No data.
Status : Modified
Published: 2020-11-13T21:15:12.817
Modified: 2024-11-21T05:23:05.117
Link: CVE-2020-28638
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD