Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/google/fscrypt: CVE-2022-25328 #248

Open
jba opened this issue Mar 1, 2022 · 0 comments
Open

Comments

@jba
Copy link
Owner

jba commented Mar 1, 2022

In CVE-2022-25328, the reference URL github.com/google/fscrypt (and possibly others) refers to something in Go.

module: github.com/google/fscrypt
package: fscrypt
description: |
    The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths.  We recommend upgrading to version 0.3.3 or above
cves:
  - CVE-2022-25328
credit: Matthias Gerstner of SUSE
links:
    pr: https://github.com/google/fscrypt/pull/346

See doc/triage.md for instructions on how to triage this report.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant