Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6224

Опубликовано: 06 июл. 2016
Источник: redhat
CVSS3: 4.7
CVSS2: 4
EPSS Низкий

Описание

ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ecryptfs-utilsNot affected
Red Hat Enterprise Linux 6ecryptfs-utilsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1356828ecryptfs-utils: ecryptfs-setup-swap improperly configures encrypted swap when using GPT partitioning on a NVMe or MMC drive

EPSS

Процентиль: 18%
0.00057
Низкий

4.7 Medium

CVSS3

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 9 лет назад

ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.

CVSS3: 3.3
nvd
больше 9 лет назад

ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.

CVSS3: 3.3
debian
больше 9 лет назад

ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap ...

CVSS3: 3.3
github
больше 3 лет назад

ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.

suse-cvrf
около 8 лет назад

Security update for ecryptfs-utils

EPSS

Процентиль: 18%
0.00057
Низкий

4.7 Medium

CVSS3

4 Medium

CVSS2