Google

Fscrypt

4 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Published 25.02.2022 11:15:08
  • Last modified 21.11.2024 06:52:00

fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fsc...

  • EPSS 0.04%
  • Published 25.02.2022 11:15:08
  • Last modified 21.11.2024 06:52:00

The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file ...

  • EPSS 0.04%
  • Published 25.02.2022 11:15:08
  • Last modified 21.11.2024 06:52:00

The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their...

  • EPSS 0.21%
  • Published 23.08.2018 19:29:01
  • Last modified 21.11.2024 04:10:54

The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that...