CVE-2018-6558 Information
Feb 14, 2021
cve
Description
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Reference
https://github.com/google/fscrypt/commit/3022c1603d968c22f147b4a2c49c4637dd1be91b https://github.com/google/fscrypt/commit/315f9b042237200174a1fb99427f74027e191d66 https://github.com/google/fscrypt/issues/77 https://launchpad.net/bugs/1787548
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
6.5
Share on: