nixpkgs
02af3cd1 - fscrypt: 0.2.3 -> 0.2.4 (security, CVE-2018-6558)

Commit
7 years ago
fscrypt: 0.2.3 -> 0.2.4 (security, CVE-2018-6558) (cherry picked from commit 4f519e5dc8d41acfc31ded7b1bbb46b55aa23e3a) Reason: Security update: "The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam)."
Author
Committer
Parents
Loading