Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Ubuntu 11.04 eCryptfs Advisory USN-1188-1: Multiple Risks Identified

ubuntu
Calendar Grey August 9, 2011
Scroller Ubuntu
eCryptfs, a secure file system for Linux, faces vulnerabilities on Ubuntu, risking unauthorized access to encrypted files and potential data breaches
eCryptfs could be tricked into mounting and unmounting arbitrary locations, and possibly disclose confidential information.

Summary

eCryptfs could be tricked into mounting and unmounting arbitrary locations,

and possibly disclose confidential information.

Software Description:

- ecryptfs-utils: ecryptfs cryptographic filesystem (utilities)

Details:

Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly

validated permissions on the requested mountpoint. A local attacker could

use this flaw to mount to arbitrary locations, leading to privilege

escalation. (CVE-2011-1831)

Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly

validated permissions on the requested mountpoint. A local attacker could

use this flaw to unmount to arbitrary locations, leading to a denial of

service. (CVE-2011-1832)

Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly

validated permissions on the requested source directory. A local attacker

could use this flaw to mount an arbitrary directory, possibly leading to

information disclosure. A pending kernel update w...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
  ecryptfs-utils                  87-0ubuntu1.1

Ubuntu 10.10:
  ecryptfs-utils                  83-0ubuntu3.2.10.10.1

Ubuntu 10.04 LTS:
  ecryptfs-utils                  83-0ubuntu3.2.10.04.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1188-1

CVE-2011-1831, CVE-2011-1832, CVE-2011-1833, CVE-2011-1834,

CVE-2011-1835, CVE-2011-1836, CVE-2011-1837

Severity
important
Lowest
Low
Medium
High
Critical

August 09, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.