CVE-2015-8013
25.07.2017, 18:29
s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrically encrypted PGP message.Enginsight
Vendor | Product | Version |
---|---|---|
openpgpjs | openpgpjs | 𝑥 ≤ 1.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References