漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
electerm's encrypt method not safe enough
Vulnerability Description
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to alter config/bookmarks. This vulnerability is fixed in 3.9.5.
CVSS Information
N/A
Vulnerability Type
不充分的加密强度
Vulnerability Title
Electerm 安全漏洞
Vulnerability Description
Electerm是中国zxdong262个人开发者的一款基于 electron 开发的 SSH/SFTP 客户端。 Electerm 3.9.5之前版本存在安全漏洞,该漏洞源于确定性AES-192-CBC使用固定零IV、常量KDF盐且无MAC,导致同步书签/配置文件数据的机密性和完整性失败,攻击者可破解常见密码并执行未检测到的密文比特翻转以更改配置/书签。
CVSS Information
N/A
Vulnerability Type
N/A