Google Fscrypt是美国谷歌(Google)公司的一个开源高级工具。用于管理 Linux 本机文件系统加密。 fscrypt存在操作系统命令注入漏洞,该漏洞的存在是由于fscrypt bash完成脚本中不正确的输入验证。未经身份验证的远程攻击者可利用该漏洞可以将专门制作的数据传递给应用程序,并在目标系统上执行任意命令。该漏洞允许远程攻击者可利用该漏洞在目标系统上执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Google LLC | fscrypt | unspecified ~ 0.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-0247 | 7.5 HIGH | Write access to VMO data through copy-on-write in Fuchsia |
| CVE-2022-25326 | 5.5 MEDIUM | Denial of Service in fscrypt |
| CVE-2022-25327 | 5.5 MEDIUM | Local Denial of Service in fscrypt PAM module |
No comments yet