Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-5188
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-5188

Description:
The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/46073

SAID
  Secunia Advisory: SA32382

OSVDB
  49334
  50353
  50354
  50355

MLIST
  http://www.openwall.com/lists/oss-security/2008/10/29/4
  http://www.openwall.com/lists/oss-security/2008/10/29/7
  http://www.openwall.com/lists/oss-security/2008/10/23/3

CONFIRM
  http://git.kernel.org/?p=linux/kernel/git/mhalcrow/ecryptfs-utils.git;a=commit;h=06de99afd53f03fe07eda0ad9d61ac6d5d4d9f53


Return to the previous page.