Skip to content

7zip Password in terminal isn't masked #97

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
ACR-Jeff opened this issue Feb 21, 2025 · 2 comments · May be fixed by #112
Open

7zip Password in terminal isn't masked #97

ACR-Jeff opened this issue Feb 21, 2025 · 2 comments · May be fixed by #112

Comments

@ACR-Jeff
Copy link

ACR-Jeff commented Feb 21, 2025

My system: Void Linux, 7zip version 24.09
Very serious security risk
When creating a 7z a -p filename.tar.7z "dirname" archive the users input isn't masked with *** or nothing visible at all while typing the password.
This only happens with 7zip while creating a password protected archive, No other observations of this within the Terminal or within the system other than 7zip.

Image

After posting I did some research and there is an existing outdated report on 7-zip's sourceforge https://sourceforge.net/p/sevenzip/bugs/2450/

@ACR-Jeff ACR-Jeff changed the title Security Vaulnerability Password in terminal isn't encrypted 7zip Password in terminal isn't encrypted Feb 21, 2025
@donaastor
Copy link

donaastor commented Mar 3, 2025

I can confirm that this happens on my system too. I installed arch and 7zip today so everything is up to date (date when I write this comment, it is "7zip 24.09-3"). It also happens when decompressing (decrypting) archives and the user doesn't have to repeat the password, it is only entered once. I understand that this is a bug since the changelog mentions not echoing passwords from 2010.

Btw, this isn't password encryption, I suggest the title: "Password is echoed in terminal" or something like that.

@ACR-Jeff
Copy link
Author

ACR-Jeff commented Mar 4, 2025

Btw, this isn't password encryption, I suggest the title: "Password is echoed in terminal" or something like that.

Correct, I was sleeping when typing lol. It's more like masking the password with *** or nothing at all visible when typing a password as standard practice. I will correct my title. Thank you for your confirmation.

@ACR-Jeff ACR-Jeff changed the title 7zip Password in terminal isn't encrypted 7zip Password in terminal isn't masked Mar 4, 2025
@srijondeb srijondeb linked a pull request Apr 23, 2025 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants