VYPR

rpm package

opensuse/fscrypt&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/fscrypt&distro=openSUSE%20Tumbleweed

Vulnerabilities (3)

  • CVE-2022-25328MedFeb 25, 2022
    affected < 0.3.3-1.1fixed 0.3.3-1.1

    The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a m

  • CVE-2022-25327MedFeb 25, 2022
    affected < 0.3.3-1.1fixed 0.3.3-1.1

    The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from

  • CVE-2022-25326MedFeb 25, 2022
    affected < 0.3.3-1.1fixed 0.3.3-1.1

    fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories wher