Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-6558

Опубликовано: 23 авг. 2018
Источник: debian
EPSS Низкий

Описание

The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
fscryptfixed0.2.4-1package

Примечания

  • https://bugs.launchpad.net/ubuntu/+source/fscrypt/+bug/1787548

  • https://github.com/google/fscrypt/issues/77

  • https://github.com/google/fscrypt/pull/103

EPSS

Процентиль: 43%
0.00206
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).

CVSS3: 6.5
nvd
больше 7 лет назад

The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).

CVSS3: 6.5
github
больше 4 лет назад

Privilege Escalation in fscrypt

EPSS

Процентиль: 43%
0.00206
Низкий