7.2

CVE-2008-5188

The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ecryptfs ≫ Ecryptfs Utils Version 45
Ecryptfs ≫ Ecryptfs Utils Version 46
Ecryptfs ≫ Ecryptfs Utils Version 47
Ecryptfs ≫ Ecryptfs Utils Version 48
Ecryptfs ≫ Ecryptfs Utils Version 49
Ecryptfs ≫ Ecryptfs Utils Version 50
Ecryptfs ≫ Ecryptfs Utils Version 51
Ecryptfs ≫ Ecryptfs Utils Version 53
Ecryptfs ≫ Ecryptfs Utils Version 54
Ecryptfs ≫ Ecryptfs Utils Version 55
Ecryptfs ≫ Ecryptfs Utils Version 56
Ecryptfs ≫ Ecryptfs Utils Version 57
Ecryptfs ≫ Ecryptfs Utils Version 58
Ecryptfs ≫ Ecryptfs Utils Version 59
Ecryptfs ≫ Ecryptfs Utils Version 60
Ecryptfs ≫ Ecryptfs Utils Version 61
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.302
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://git.kernel.org/?p=linux/kernel/git/mhalcrow/ecryptfs-utils.git%3Ba=commit%3Bh=06de99afd53f03fe07eda0ad9d61ac6d5d4d9f53
http://osvdb.org/49334
http://osvdb.org/50353
http://osvdb.org/50354
http://osvdb.org/50355
http://rhn.redhat.com/errata/RHSA-2009-1307.html
http://secunia.com/advisories/32382
http://secunia.com/advisories/36552
http://www.openwall.com/lists/oss-security/2008/10/23/3
http://www.openwall.com/lists/oss-security/2008/10/29/4
http://www.openwall.com/lists/oss-security/2008/10/29/7
https://exchange.xforce.ibmcloud.com/vulnerabilities/46073
https://launchpad.net/bugs/287908
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9607