Lucene search

K
cveMitreCVE-2008-5188
HistoryNov 21, 2008 - 2:30 a.m.

CVE-2008-5188

2008-11-2102:30:00
CWE-255
mitre
web.nvd.nist.gov
38
ecryptfs
security vulnerability
cleartext passwords
local users
sensitive information

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

5.5

Confidence

Low

EPSS

0

Percentile

10.1%

The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.

Affected configurations

Nvd
Node
ecryptfsecryptfs_utilsMatch45
OR
ecryptfsecryptfs_utilsMatch46
OR
ecryptfsecryptfs_utilsMatch47
OR
ecryptfsecryptfs_utilsMatch48
OR
ecryptfsecryptfs_utilsMatch49
OR
ecryptfsecryptfs_utilsMatch50
OR
ecryptfsecryptfs_utilsMatch51
OR
ecryptfsecryptfs_utilsMatch53
OR
ecryptfsecryptfs_utilsMatch54
OR
ecryptfsecryptfs_utilsMatch55
OR
ecryptfsecryptfs_utilsMatch56
OR
ecryptfsecryptfs_utilsMatch57
OR
ecryptfsecryptfs_utilsMatch58
OR
ecryptfsecryptfs_utilsMatch59
OR
ecryptfsecryptfs_utilsMatch60
OR
ecryptfsecryptfs_utilsMatch61
VendorProductVersionCPE
ecryptfsecryptfs_utils45cpe:2.3:a:ecryptfs:ecryptfs_utils:45:*:*:*:*:*:*:*
ecryptfsecryptfs_utils46cpe:2.3:a:ecryptfs:ecryptfs_utils:46:*:*:*:*:*:*:*
ecryptfsecryptfs_utils47cpe:2.3:a:ecryptfs:ecryptfs_utils:47:*:*:*:*:*:*:*
ecryptfsecryptfs_utils48cpe:2.3:a:ecryptfs:ecryptfs_utils:48:*:*:*:*:*:*:*
ecryptfsecryptfs_utils49cpe:2.3:a:ecryptfs:ecryptfs_utils:49:*:*:*:*:*:*:*
ecryptfsecryptfs_utils50cpe:2.3:a:ecryptfs:ecryptfs_utils:50:*:*:*:*:*:*:*
ecryptfsecryptfs_utils51cpe:2.3:a:ecryptfs:ecryptfs_utils:51:*:*:*:*:*:*:*
ecryptfsecryptfs_utils53cpe:2.3:a:ecryptfs:ecryptfs_utils:53:*:*:*:*:*:*:*
ecryptfsecryptfs_utils54cpe:2.3:a:ecryptfs:ecryptfs_utils:54:*:*:*:*:*:*:*
ecryptfsecryptfs_utils55cpe:2.3:a:ecryptfs:ecryptfs_utils:55:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

5.5

Confidence

Low

EPSS

0

Percentile

10.1%