The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password.
References
Configurations
History
21 Nov 2024, 02:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://hmarco.org/bugs/CVE-2016-4484/CVE-2016-4484_cryptsetup_initrd_shell.html - Exploit, Mitigation, Technical Description, Third Party Advisory | |
References | () http://www.openwall.com/lists/oss-security/2016/11/14/13 - Mailing List, Third Party Advisory | |
References | () http://www.openwall.com/lists/oss-security/2016/11/15/1 - Mailing List, Third Party Advisory | |
References | () http://www.openwall.com/lists/oss-security/2016/11/15/4 - Mailing List, Third Party Advisory | |
References | () http://www.openwall.com/lists/oss-security/2016/11/16/6 - Mailing List, Third Party Advisory | |
References | () http://www.securityfocus.com/bid/94315 - | |
References | () https://gitlab.com/cryptsetup/cryptsetup/commit/ef8a7d82d8d3716ae9b58179590f7908981fa0cb - Patch |
Information
Published : 2017-01-23 21:59
Updated : 2024-11-21 02:52
NVD link : CVE-2016-4484
Mitre link : CVE-2016-4484
CVE.ORG link : CVE-2016-4484
JSON object : View
Products Affected
cryptsetup_project
- cryptsetup
CWE
CWE-287
Improper Authentication