CVE Database
/

CVE-2018-6558

Back to search

CVE-2018-6558

Published: Aug 23, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).

VendorProductVersions

The fscrypt Project

fscrypt

affected
before 0.2.4

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now