Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1obTM3LTl4aDItcTQ5Oc4AAtHw

Possible leak of key's raw field if declared length is incorrect

Impact

If a field of a key is shorter than it is declared to be, the parser raises an error with a message containing the raw field value. An attacker able to modify the declared length of a key's sensitive field can thus expose the raw value of that field.

Patches

Upgrade to version 0.0.6, which no longer includes the raw field value in the error message.

Workarounds

N/A

References

N/A

For more information

If you have any questions or comments about this advisory:

Permalink: https://github.com/advisories/GHSA-hm37-9xh2-q499
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1obTM3LTl4aDItcTQ5Oc4AAtHw
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: over 1 year ago


CVSS Score: 7.7
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Identifiers: GHSA-hm37-9xh2-q499, CVE-2022-31124
References: Repository: https://github.com/scottcwang/openssh_key_parser
Blast Radius: 0.0

Affected Packages

pypi:openssh-key-parser
Dependent packages: 0
Dependent repositories: 1
Downloads: 281 last month
Affected Version Ranges: < 0.0.6
Fixed in: 0.0.6
All affected versions: 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.0.5
All unaffected versions: 0.0.6, 0.0.7