CVE-2008-5188

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
21/11/2008
Last modified:
09/04/2025

Description

The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ecryptfs:ecryptfs_utils:45:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:46:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:47:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:48:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:49:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:50:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:51:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:53:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:54:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:55:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:56:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:57:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:58:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:59:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs_utils:60:*:*:*:*:*:*:*