Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qj26-7grj-whg3

Опубликовано: 23 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Privilege Escalation in fscrypt

The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).

Пакеты

Наименование

github.com/google/fscrypt

go
Затронутые версииВерсия исправления

< 0.2.4

0.2.4

EPSS

Процентиль: 43%
0.00206
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).

CVSS3: 6.5
nvd
больше 7 лет назад

The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).

CVSS3: 6.5
debian
больше 7 лет назад

The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore ...

EPSS

Процентиль: 43%
0.00206
Низкий

6.5 Medium

CVSS3