CVE-2016-4484: Medium severity Cryptsetup Project Cryptsetup vulnerability
Published Jan 23, 2017
·Updated
The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password.
Affected Software
1 affected component
Cryptsetup Project Cryptsetup<=2.1.7.3-2
Remediation
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 12, 58332
Event
08:32 AM
Frequently Asked Questions
1
What is the severity of CVE-2016-4484?
CVE-2016-4484 is considered to have a medium severity level due to the potential for unauthorized shell access.
2
How do I fix CVE-2016-4484?
To fix CVE-2016-4484, upgrade the cryptsetup package to version 2:1.7.3-3 or higher.
3
Who is affected by CVE-2016-4484?
Users of the cryptsetup package version 2:1.7.3-2 and earlier on Debian systems are affected by CVE-2016-4484.
4
What type of attack does CVE-2016-4484 allow?
CVE-2016-4484 allows physically proximate attackers to gain shell access through repeated login attempts with incorrect passwords.
5
When was CVE-2016-4484 disclosed?
CVE-2016-4484 was disclosed in November 2016.