Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w4f8-fxq2-j35v

Опубликовано: 01 мар. 2022
Источник: github
Github: Прошло ревью

Описание

Possible privilege escalation via bash completion script

The bash completion script for fscrypt through v0.3.2 allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to v0.3.3 or above.

For more details, see CVE-2022-25328.

Пакеты

Наименование

github.com/google/fscrypt

go
Затронутые версииВерсия исправления

< 0.3.3

0.3.3