Skip to content

[URGENT] Security Vulnerability #18

@maennchen

Description

@maennchen

Since I haven't found your email, I encrypted the following report using your public keys on GitHub. If you have problems reading this message please contact me either here or via jonatan [at] maennchen.ch.

Message

Encrypted

-----BEGIN PGP MESSAGE-----

jA0EBwMCbOWZ0ZuGT7Pl0ukB8GfeG/GD+SL5+5fiV+aoezuZqEUXPDgaYlSjoH/O
0AlOi1QGVmuhEZTOV/G5w+txmfvYlSYXhUHQ6gwvhzrIxS7RZ31rDlWAQYauS0/d
ixVCQzhxyh2sNN+EF68PmPNJH72R3tX2JWXdUkeD5E/k4+ICynHcjhebgk97Ka8y
uFbay8sasC2DXmPtQ1oDuizdSAsB6hOtDtzo4H6VFvXJ4jV/yWguFKdpaJOXRQYj
PPbkIoX7slMoBvBkxRo/eUqeEwapInlWndPgQdIbmfZk6t9qij7RsmZ3ZOFZASHR
tHl2k0eFKt+GDInW1gUmmCce9pK5r3uMF5ayse8rcH2gAqnMxx8+2xAzq2C2PB4u
mhCwxvzukRQF0mIQL94d818RYR9QAvWO3IFxWDIH/gLCCvaxl96SOwYI0F30Uqbe
Yqz40qYG7HUHBbYDekw8Y+vhU6JCRv+85kZXa7tedA5lcV+m0ajOe7d2bLg7jTzl
niRu0ymvDLR8orsb2E4BrV5HFFV8M0rfsTcabG/3qDZg3Xh/L5OX/xi9EkEcRJa/
Ni9hHfBJWmnojyeTzz07AAvzsP44aqncFuYBQAnKnG+57UzQSSQBVoJDWWJNgRa5
JfCdS7CRYphv86+YmtGALQWo9lIYkZ0iNFeWNYs0N0Nh7IFPSofTleSgubxdNGxK
e8BUplUX90By1B1sspgsbUXKnuXiF/qjcqMXNNu0gSYawuEobp1380gt4XZAYTwb
x5VrQTZAknraM4I4lPENfbpshhqS+H/kdPBmNM4n6AWjb7tq5RRv6QR6YlV9nwHe
TSVZQDP0FyCd0kizLS1XPhap5mf0ip56BTqstW9XuWj6rXH1wqBq2QmzvqhzxY76
LJO1xHsRBggGE4p1v3/zpQhIsOYsCzS7s1uGhtrYUSjzJr471mTAky35w5iscP6h
VHAa3Bwrzm4tsHe/rVaT9YkQhRkcdCJAkRYABPfq597zIn/Fv4CDZuxEBzPM3wiQ
Ww3vw2SHTRNkBCi0Bqgo1sOxKJFtjYRH3v3AFpiEo/rnkFrrC5LW
=MlWk
-----END PGP MESSAGE-----

Encrypted Keys

DRPoJRRSbYnzQHFrgqvWJS/LePbhlEUqnKnECi6DLGZ4bsmJZdhyrbI67DzE3XisNlg24cij/QEvJZj5LoDS+LTQHSZWr2n37H58Ex14wuH9oG26OXYP+/pUkuv2B/FkPzIPjXBRYgy7l05t9oTajVR9zxYzr8pFI46/E1A4SnOFwLNuMgZxQ8FMlQ6Gm2Zs/Eiskqq1Nasv7VUq+ywx8Fg3+1cL4cywoVsEJ+OzozwQBjhQyBWLH0+RNCIQWyNsB+C99mcvN4D8v45Xt/YPswPtZDRRIiFKv8Q8Hws8Nw5On9msEIzDrPdEGcwxLgjgqri7+ZWbGV6J4g36ZVRqjA==
Ss4uHA9R8m24YeW79AZJk1HbwPkdzmO3KsroEqY5Efsz9gJGNWwv25zKwl7/bB601GSPHXq0htoPUpAJeJsV46rW2Zdpicym9LrbXLJz2P4/CIaQVV5s5X9PZczmUHxZUSeKqiHha7voztxNlCyc+bFzY54X86TV7VA9Oa3j9fRBwO4tYNaOB8Pp6aZ0eiDusSVNz1ncNsAn+VxomAvkpVb3jaEGUFeV/EnBTQI9juTzD8V8s65NIPiGt16k+qY5bGmnEHz/an6mVMEKMULKJKpYrzDgvHW9y9zo2dDI2sg795Pzfuk9akolELFzXXeg3S+rUgCWBngYJZge/8n6kw==

Decryption

openssl rsautl -decrypt -ssl -inkey ~/.ssh/id_rsa -in secret.txt.key.enc -out secret.txt.key
gpg -d --pinentry-mode loopback --passphrase-file ./secret.txt.key  --armor [MESSAGE]

Responsible Disclosure

After the time for responsible disclosure has passed, I'll comment the password for the message here.

EDIT: I have some additional information, please contact me before you fix anything.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions