Re: [SECURITY ALERT] Kleopatra allows local users to execute arbitrary code

2021-02-01 Thread René J . V . Bertin
On Thursday January 28 2021 08:49:50 Andre Heinecke wrote: >Ok, its a bug but I don't think this is really a security isse +++ >From what I understand the bug is that a file is executed instead of being >encrypted/decrypted. This could be a security risk on a proper OS where it would allow use

Re: [SECURITY ALERT] Kleopatra allows local users to execute arbitrary code

2021-01-31 Thread Hoàng Cường
Hi Andre, I think this is a security issue, the file execution is out of control. This security issue has been recognized and fixed by many organizations. Ref: - https://trioxsecurity.com/intel-audio-driver-unquoted-service-path-vulnerability/ - https://hackerone.com/reports/716448 - https://apps

Re: [SECURITY ALERT] Kleopatra allows local users to execute arbitrary code

2021-01-31 Thread Andre Heinecke
Hi, Thanks for the report. On Thursday 28 January 2021 05:59:01 CET Hoàng Cường wrote: > I discovered security vulnerabilities in Kleopatra , tested on Kleopatra > Version 3.1.8-gpg4win-3.1.10.latest update. > > #sumary: > - Unquoted program path in Kleopatra allows local users to execute > arbi