PT-2022-4970 · Aes Crypt · Aescrypt

CVE-2022-35928

·

Published

2022-07-15

·

Updated

2023-06-29

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AES Crypt version 3.11
Description The issue is related to reading user-provided passwords and confirmations via command-line prompts in AES Crypt for Linux. Password lengths were not checked before being read, which may lead to buffer overruns. This vulnerability does not affect source code found on aescrypt.com, nor is it present when providing a password or a key via the -p or -k command-line options.
Recommendations For AES Crypt version 3.11, users are advised to upgrade to release 3.16 to fix the issue. Users unable to upgrade should use the -p or -k options to provide a password or key.

Exploit

Fix

Improper Authentication

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06164
CVE-2022-35928
GHSA-R7FV-72PG-FWRQ

Affected Products

Aescrypt