CVE-2008-5188
published 2008-11-21CVE-2008-5188: The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs…
PriorityP422high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.39%
30.8th percentile
The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ecryptfs-utils | < ecryptfs-utils 66-1 (bookworm) | ecryptfs-utils 66-1 (bookworm) |
| ecryptfs | ecryptfs-utils | >= 0 < 66-1 | 66-1 |
| ecryptfs | ecryptfs-utils | >= 0 < 66-1 | 66-1 |
| ecryptfs | ecryptfs-utils | >= 0 < 66-1 | 66-1 |
| ecryptfs | ecryptfs-utils | >= 0 < 66-1 | 66-1 |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
| ecryptfs | ecryptfs_utils | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-84hq-4h95-83xw: The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped
ghsa_unreviewed·2022-05-17
CVE-2008-5188 [HIGH] GHSA-84hq-4h95-83xw: The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped
The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.
OSV
CVE-2008-5188: The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped
osv·2008-11-21·CVSS 7.2
CVE-2008-5188 [HIGH] CVE-2008-5188: The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped
The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.
Red Hat
ecryptfs-utils: potential provided password disclosure in the process table
vendor_redhat·2008-10-23·CVSS 7.2
CVE-2008-5188 [HIGH] ecryptfs-utils: potential provided password disclosure in the process table
ecryptfs-utils: potential provided password disclosure in the process table
The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.
Debian
CVE-2008-5188: ecryptfs-utils - The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptf...
vendor_debian·2008·CVSS 7.2
CVE-2008-5188 [HIGH] CVE-2008-5188: ecryptfs-utils - The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptf...
The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.
Scope: local
bookworm: resolved (fixed in 66-1)
bullseye: resolved (fixed in 66-1)
forky: resolved (fixed in 66-1)
sid: resolved (fixed in 66-1)
trixie: resolved (fixed in 66-1)
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/mhalcrow/ecryptfs-utils.git%3Ba=commit%3Bh=06de99afd53f03fe07eda0ad9d61ac6d5d4d9f53http://osvdb.org/49334http://osvdb.org/50353http://osvdb.org/50354http://osvdb.org/50355http://rhn.redhat.com/errata/RHSA-2009-1307.htmlhttp://secunia.com/advisories/32382http://secunia.com/advisories/36552http://www.openwall.com/lists/oss-security/2008/10/23/3http://www.openwall.com/lists/oss-security/2008/10/29/4http://www.openwall.com/lists/oss-security/2008/10/29/7https://exchange.xforce.ibmcloud.com/vulnerabilities/46073https://launchpad.net/bugs/287908https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9607http://git.kernel.org/?p=linux/kernel/git/mhalcrow/ecryptfs-utils.git%3Ba=commit%3Bh=06de99afd53f03fe07eda0ad9d61ac6d5d4d9f53http://osvdb.org/49334http://osvdb.org/50353http://osvdb.org/50354http://osvdb.org/50355http://rhn.redhat.com/errata/RHSA-2009-1307.htmlhttp://secunia.com/advisories/32382http://secunia.com/advisories/36552http://www.openwall.com/lists/oss-security/2008/10/23/3http://www.openwall.com/lists/oss-security/2008/10/29/4http://www.openwall.com/lists/oss-security/2008/10/29/7https://exchange.xforce.ibmcloud.com/vulnerabilities/46073https://launchpad.net/bugs/287908https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9607
2008-11-21
Published