Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
eCryptfs could be tricked into mounting and unmounting arbitrary locations,
and possibly disclose confidential information.
Software Description:
- ecryptfs-utils: ecryptfs cryptographic filesystem (utilities)
Details:
Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly
validated permissions on the requested mountpoint. A local attacker could
use this flaw to mount to arbitrary locations, leading to privilege
escalation. (CVE-2011-1831)
Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly
validated permissions on the requested mountpoint. A local attacker could
use this flaw to unmount to arbitrary locations, leading to a denial of
service. (CVE-2011-1832)
Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly
validated permissions on the requested source directory. A local attacker
could use this flaw to mount an arbitrary directory, possibly leading to
information disclosure. A pending kernel update w...
The problem can be corrected by updating your system to the following package versions: Ubuntu 11.04: ecryptfs-utils 87-0ubuntu1.1 Ubuntu 10.10: ecryptfs-utils 83-0ubuntu3.2.10.10.1 Ubuntu 10.04 LTS: ecryptfs-utils 83-0ubuntu3.2.10.04.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-1188-1
CVE-2011-1831, CVE-2011-1832, CVE-2011-1833, CVE-2011-1834,
CVE-2011-1835, CVE-2011-1836, CVE-2011-1837
Get the latest Linux and open source security news straight to your inbox.