First published: Fri Nov 21 2008(Updated: )
The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
eCryptfs-utils | =49 | |
eCryptfs-utils | =55 | |
eCryptfs-utils | =51 | |
eCryptfs-utils | =57 | |
eCryptfs-utils | =47 | |
eCryptfs-utils | =60 | |
eCryptfs-utils | =58 | |
eCryptfs-utils | =50 | |
eCryptfs-utils | =61 | |
eCryptfs-utils | =45 | |
eCryptfs-utils | =54 | |
eCryptfs-utils | =53 | |
eCryptfs-utils | =46 | |
eCryptfs-utils | =56 | |
eCryptfs-utils | =59 | |
eCryptfs-utils | =48 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5188 is considered a moderate severity vulnerability due to the cleartext exposure of sensitive information.
To fix CVE-2008-5188, update to a version of eCryptfs-utils that has addressed this vulnerability.
CVE-2008-5188 affects multiple versions of eCryptfs-utils, including versions 45 through 61.
CVE-2008-5188 allows local users to access cleartext passwords placed on command lines by the affected scripts.
CVE-2008-5188 can be exploited by local users who have sufficient permissions to list running processes.