The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://git.kernel.org/?p=linux/kernel/git/mhalcrow/ecryptfs-utils.git%3Ba=commit%3Bh=06de99afd53f03fe07eda0ad9d61ac6d5d4d9f53 - | |
References | () http://osvdb.org/49334 - | |
References | () http://osvdb.org/50353 - | |
References | () http://osvdb.org/50354 - | |
References | () http://osvdb.org/50355 - | |
References | () http://rhn.redhat.com/errata/RHSA-2009-1307.html - | |
References | () http://secunia.com/advisories/32382 - | |
References | () http://secunia.com/advisories/36552 - | |
References | () http://www.openwall.com/lists/oss-security/2008/10/23/3 - | |
References | () http://www.openwall.com/lists/oss-security/2008/10/29/4 - | |
References | () http://www.openwall.com/lists/oss-security/2008/10/29/7 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/46073 - | |
References | () https://launchpad.net/bugs/287908 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9607 - |
07 Nov 2023, 02:03
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2008-11-21 02:30
Updated : 2024-11-21 00:53
NVD link : CVE-2008-5188
Mitre link : CVE-2008-5188
CVE.ORG link : CVE-2008-5188
JSON object : View
Products Affected
ecryptfs
- ecryptfs_utils
CWE
CWE-255
Credentials Management Errors