4.9
CVSSv2

CVE-2018-6558

Published: 23/08/2018 Updated: 03/10/2019
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:P

Vulnerability Summary

The pam_fscrypt module in fscrypt prior to 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows malicious users to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google fscrypt

Vendor Advisories

Debian Bug report logs - #907074 fscrypt: CVE-2018-6558 Package: src:fscrypt; Maintainer for src:fscrypt is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 23 Aug 2018 19:18:01 UTC Severity: grave Tags: fixed-upstream, security, upstream Fou ...