oss-sec mailing list archives
CVE-2016-4484: - Cryptsetup Initrd root Shell
From: Hector Marco <hmarco () hmarco org>
Date: Mon, 14 Nov 2016 20:45:51 +0000
Hello All, Affected package ---------------- Cryptsetup <= 2:1 CVE-ID ------ CVE-2016-4484 Description ----------- A vulnerability in Cryptsetup, concretely in the scripts that unlock the system partition when the partition is ciphered using LUKS (Linux Unified Key Setup). This vulnerability allows to obtain a root initramfs shell on affected systems. The vulnerability is very reliable because it doesn't depend on specific systems or configurations. Attackers can copy, modify or destroy the hard disc as well as set up the network to exflitrate data. In cloud environments it is also possible to remotely exploit this vulnerability without having "physical access." Full description: ----------------- http://hmarco.org/bugs/CVE-2016-4484/CVE-2016-4484_cryptsetup_initrd_shell.html Regards, Hector Marco & Ismael Ripoll.
Attachment:
signature.asc
Description: OpenPGP digital signature
Current thread:
- CVE-2016-4484: - Cryptsetup Initrd root Shell Hector Marco (Nov 14)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell - Update: Dracut is also vulnerable Hector Marco-Gisbert (Nov 14)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell Leo Famulari (Nov 14)
- Re: [FD] [oss-security] CVE-2016-4484: - Cryptsetup Initrd root Shell Hector Marco (Nov 15)
- Re: Re: [FD] [oss-security] CVE-2016-4484: - Cryptsetup Initrd root Shell Jeremy Stanley (Nov 15)
- Re: [FD] [oss-security] CVE-2016-4484: - Cryptsetup Initrd root Shell Hector Marco (Nov 15)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell Jason Cooper (Nov 16)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell John Haxby (Nov 16)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell Jason Cooper (Nov 17)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell John Haxby (Nov 17)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell Jason Cooper (Nov 17)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell John Haxby (Nov 17)
- Re: CVE-2016-4484: - Cryptsetup Initrd root Shell John Haxby (Nov 16)