Several problems have been discovered in ecryptfs-utils, a cryptographic
filesystem for Linux.
CVE-2011-1831
Vasiliy Kulikov of Openwall and Dan Rosenberg discovered that eCryptfs
incorrectly validated permissions on the requested mountpoint. A local
attacker could use this flaw to mount to arbitrary locations, leading
to privilege escalation.
CVE-2011-1832
Vasiliy Kulikov of Openwall and Dan Rosenberg discovered that eCryptfs
incorrectly validated permissions on the requested mountpoint. A local
attacker could use this flaw to unmount to arbitrary locations, leading
to a denial of service.
CVE-2011-1834
Dan Rosenberg and Marc Deslauriers discovered that eCryptfs incorrectly
handled modifications to the mtab file when an error occurs. A local
attacker could use this flaw to corrupt the mtab file, and possibly
unmount arbitrary locations, leading to a denial of service.
CVE-2011-1835
Marc Deslauriers discovered that eCryptfs incorrectly handled keys when
setting up an encryp...
Get the latest Linux and open source security news straight to your inbox.