Comparison using wrong factors in tough - CVE-2025-2888

 

Comparison using wrong factors in tough - CVE-2025-2888

Published: March 28, 2025


Vulnerability identifier: #VU106241
CSH Severity: Low
CVSS v4: 5.6 [CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-2888
CWE-ID: CWE-1025
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the target system.

The vulnerability exists due to timestamp metadata is cached when it fails snapshot rollback check. A remote administrator can cause the affected software to subsequently incorrectly identify valid timestamp metadata as being rolled back, preventing the client from consuming valid updates.


Affected software

tough

How to mitigate CVE-2025-2888

Install updates from vendor's website.

tough - update to 0.20.0

External References

Related Security Bulletins