Jahlives

Openssl Encrypt

66 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 27.08.2026 14:51:15
  • Zuletzt bearbeitet 02.09.2026 13:15:35

openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily large A...

  • EPSS 0.13%
  • Veröffentlicht 27.08.2026 14:51:14
  • Zuletzt bearbeitet 03.09.2026 15:09:57

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to local identity stores can craf...

  • EPSS 0.32%
  • Veröffentlicht 27.08.2026 14:51:13
  • Zuletzt bearbeitet 02.09.2026 13:15:43

openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at import tim...

  • EPSS 0.13%
  • Veröffentlicht 27.08.2026 14:51:12
  • Zuletzt bearbeitet 23.09.2026 17:17:42

openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers who obtain keyfiles or e...

  • EPSS 0.09%
  • Veröffentlicht 27.08.2026 14:51:12
  • Zuletzt bearbeitet 02.09.2026 13:20:18

openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._verify_integrity_...

  • EPSS 0.19%
  • Veröffentlicht 27.08.2026 14:51:11
  • Zuletzt bearbeitet 02.09.2026 13:09:05

openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin without the READ_FILES permission could read ...

  • EPSS 0.19%
  • Veröffentlicht 27.08.2026 14:51:10
  • Zuletzt bearbeitet 03.09.2026 15:09:44

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize_argv_for_debug fails to sanitize it. As a r...

  • EPSS 0.14%
  • Veröffentlicht 27.08.2026 14:51:09
  • Zuletzt bearbeitet 02.09.2026 13:09:21

openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, ~32-bit) GPG key id could unknowingly enrol...

  • EPSS 0.41%
  • Veröffentlicht 27.08.2026 14:51:09
  • Zuletzt bearbeitet 23.09.2026 17:17:42

openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identit...

  • EPSS 0.13%
  • Veröffentlicht 27.08.2026 14:51:08
  • Zuletzt bearbeitet 01.09.2026 17:57:53

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own ide...