CVE-2020-11932
LOWSubiquity < 20.05.2 - Sensitive Information Exposure via Log File
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2020-11932. PoCs published by ProjectorBUg, Staubgeborener, code-developers.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2020-11932, a double-free vulnerability in WhatsApp. The exploit generates a malicious GIF file that, when processed by the victim's WhatsApp, triggers a double-free condition leading to remote code execution via a reverse shell.
Description
It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.
Exploits (3)
This repository contains a proof-of-concept exploit for CVE-2020-11932, a double-free vulnerability in WhatsApp. The exploit generates a malicious GIF file that, when processed by the victim's WhatsApp, triggers a double-free condition leading to remote code execution via a reverse shell.
This repository provides a scanner for CVE-2020-11932, which involves plaintext logging of LUKS full disk encryption passwords in Ubuntu Server 20.04. The script checks specific log files for exposed passwords.
This repository contains a proof-of-concept exploit for CVE-2020-11932, a double-free vulnerability in WhatsApp. The exploit generates a malicious GIF file that, when processed by the victim's WhatsApp, triggers a double-free condition leading to remote code execution via a reverse shell.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N