UBUNTU-CVE-2022-25328
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-25328
Summary:
Details: The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above
References: https://ubuntu.com/security/CVE-2022-25328, https://www.openwall.com/lists/oss-security/2022/02/24/1, https://github.com/google/fscrypt/commit/fa1a1fdbdea65829ce24a6b6f86ce2961e465b02, https://www.cve.org/CVERecord?id=CVE-2022-25328
Affected packages
Package
Name: fscrypt
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
