by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
11 packages
- wormhole-rs
- magic-wormhole-rs
- python312Packages.magic-wormhole
- python313Packages.magic-wormhole
- python314Packages.magic-wormhole
- python312Packages.magic-wormhole-transit-relay
- python313Packages.magic-wormhole-transit-relay
- python314Packages.magic-wormhole-transit-relay
- python312Packages.magic-wormhole-mailbox-server
- python313Packages.magic-wormhole-mailbox-server
- python314Packages.magic-wormhole-mailbox-server
- @LeSuisse accepted
- @LeSuisse published on GitHub
Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite
Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a file (wormhole receive) from a malicious party could result in overwriting critical local files, including ~/.ssh/authorized_keys and .bashrc. This could be used to compromise the receiver's computer. Only the sender of the file (the party who runs wormhole send) can mount the attack. Other parties (including the transit/relay servers) are excluded by the wormhole protocol. This vulnerability is fixed in 0.23.0.
References
Affected products
- ==>= 0.21.0, < 0.23.0
Matching in nixpkgs
Ignored packages (11)
pkgs.wormhole-rs
Rust implementation of Magic Wormhole, with new features and enhancements
pkgs.magic-wormhole-rs
Rust implementation of Magic Wormhole, with new features and enhancements
pkgs.python312Packages.magic-wormhole
Securely transfer data between computers
pkgs.python313Packages.magic-wormhole
Securely transfer data between computers
pkgs.python314Packages.magic-wormhole
Securely transfer data between computers
pkgs.python312Packages.magic-wormhole-transit-relay
Transit Relay server for Magic-Wormhole
pkgs.python313Packages.magic-wormhole-transit-relay
Transit Relay server for Magic-Wormhole
pkgs.python314Packages.magic-wormhole-transit-relay
Transit Relay server for Magic-Wormhole
pkgs.python312Packages.magic-wormhole-mailbox-server
Securely transfer data between computers
pkgs.python313Packages.magic-wormhole-mailbox-server
Securely transfer data between computers
pkgs.python314Packages.magic-wormhole-mailbox-server
Securely transfer data between computers
Package maintainers
-
@mjoerg Martin Joerg <martin.joerg@gmail.com>