UbuntuUpdates.org

Package "fscrypt"

Name: fscrypt

Description:

Tool for managing Linux filesystem encryption

Latest version: 0.2.2-0ubuntu2.1
Release: bionic (18.04)
Level: updates
Repository: universe
Homepage: https://github.com/google/fscrypt

Links


Download "fscrypt"


Other versions of "fscrypt" in Bionic

Repository Area Version
security universe 0.2.2-0ubuntu2.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 0.2.2-0ubuntu2.1 2018-08-24 05:06:37 UTC

  fscrypt (0.2.2-0ubuntu2.1) bionic-security; urgency=medium

  * SECURITY UPDATE: Privilege escalation via improperly restored
    supplementary groups in libpam-fscrypt (LP: #1787548)
    - CVE-2018-6558.patch: Save the euid, egid, and supplementary groups when
      entering the PAM module, drop privileges to perform actions on behalf of
      the user, and then properly restore the saved values before exiting the
      PAM module. Based on patch from upstream.
    - CVE-2018-6558
  * 0001-security-drop-and-regain-privileges-in-all-threads.patch: Drop and
    regain privileges in all threads of the current process
  * 0001-Ensure-keyring-privilege-changes-are-reversible.patch: Ensure keyring
    privilege changes are reversible to prevent failures when, for example,
    "su <user>" is executed as an unprivileged user

 -- Tyler Hicks <email address hidden> Wed, 22 Aug 2018 18:57:26 +0000

1787548 PAM fscrypt adds root(0) group to all users called by su
CVE-2018-6558 privilege escalation



About   -   Send Feedback to @ubuntu_updates