Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian 7 Stable: DSA-2382-1 Moderate: ecryptfs-utils Privilege Escalation

debian
Calendar Grey January 7, 2012
Debian Logo
A variety of vulnerabilities addressed in ecryptfs-utils through security enhancement for Debian systems. Update advised to improve security measures.
Several problems have been discovered in ecryptfs-utils, a cryptographic filesystem for Linux

Summary

Several problems have been discovered in ecryptfs-utils, a cryptographic
filesystem for Linux.

CVE-2011-1831

Vasiliy Kulikov of Openwall and Dan Rosenberg discovered that eCryptfs
incorrectly validated permissions on the requested mountpoint. A local
attacker could use this flaw to mount to arbitrary locations, leading
to privilege escalation.

CVE-2011-1832

Vasiliy Kulikov of Openwall and Dan Rosenberg discovered that eCryptfs
incorrectly validated permissions on the requested mountpoint. A local
attacker could use this flaw to unmount to arbitrary locations, leading
to a denial of service.

CVE-2011-1834

Dan Rosenberg and Marc Deslauriers discovered that eCryptfs incorrectly
handled modifications to the mtab file when an error occurs. A local
attacker could use this flaw to corrupt the mtab file, and possibly
unmount arbitrary locations, leading to a denial of service.

CVE-2011-1835

Marc Deslauriers discovered that eCryptfs incorrectly handled keys when
setting up an encryp...

Read the Full Advisory

Package: ecryptfs-utils
CVE ID: CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here