Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-1572

Опубликовано: 20 янв. 2016
Источник: redhat
CVSS2: 6
EPSS Низкий

Описание

mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ecryptfs-utilsNot affected
Red Hat Enterprise Linux 6ecryptfs-utilsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1300594ecryptfs-utils: privilege escalation by mounting over /proc/$pid

EPSS

Процентиль: 14%
0.00045
Низкий

6 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.4
ubuntu
около 10 лет назад

mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.

CVSS3: 8.4
nvd
около 10 лет назад

mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.

CVSS3: 8.4
debian
около 10 лет назад

mount.ecryptfs_private.c in eCryptfs-utils does not validate mount des ...

CVSS3: 8.4
github
больше 3 лет назад

mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.

suse-cvrf
около 10 лет назад

Security update for ecryptfs-utils

EPSS

Процентиль: 14%
0.00045
Низкий

6 Medium

CVSS2