Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24718
HistoryApr 10, 2020 - 1:02 a.m.

Access Control Bypass

2020-04-1001:02:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

EPSS

0

Percentile

5.1%

encryptfs-utils is vulnerable to access control bypass. An insecure temporary file use flaw was found in the ecryptfs-setup-private script. A local attacker could use this script to insert their own key that will subsequently be used by a new user, possibly giving the attacker access to the user’s encrypted data if existing file permissions allow access.