7.3
CVSSv3

CVE-2022-25328

Published: 25/02/2022 Updated: 07/03/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.3 | Impact Score: 5.9 | Exploitability Score: 1.3
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google fscrypt

Vendor Advisories

Debian Bug report logs - #1006485 fscrypt: CVE-2022-25326 CVE-2022-25327 CVE-2022-25328 Package: src:fscrypt; Maintainer for src:fscrypt is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 26 Feb 2022 09:36:02 UTC Severity: grave Tags: securit ...