[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2382-1 ecryptfs-utils -- multiple

ID: oval:org.secpod.oval:def:600706Date: (C)2012-01-30   (M)2022-10-10
Class: PATCHFamily: unix




Several problems have been discovered in ecryptfs-utils, a cryptographic filesystem for Linux. CVE-2011-1831 Vasiliy Kulikov of Openwall and Dan Rosenberg discovered that eCryptfs incorrectly validated permissions on the requested mountpoint. A local attacker could use this flaw to mount to arbitrary locations, leading to privilege escalation. CVE-2011-1832 Vasiliy Kulikov of Openwall and Dan Rosenberg discovered that eCryptfs incorrectly validated permissions on the requested mountpoint. A local attacker could use this flaw to unmount to arbitrary locations, leading to a denial of service. CVE-2011-1834 Dan Rosenberg and Marc Deslauriers discovered that eCryptfs incorrectly handled modifications to the mtab file when an error occurs. A local attacker could use this flaw to corrupt the mtab file, and possibly unmount arbitrary locations, leading to a denial of service. CVE-2011-1835 Marc Deslauriers discovered that eCryptfs incorrectly handled keys when setting up an encrypted private directory. A local attacker could use this flaw to manipulate keys during creation of a new user. CVE-2011-1837 Vasiliy Kulikov of Openwall discovered that eCryptfs incorrectly handled lock counters. A local attacker could use this flaw to possibly overwrite arbitrary files. We acknowledge the work of the Ubuntu distribution in preparing patches suitable for near-direct inclusion in the Debian package.

Platform:
Debian 5.0
Debian 6.0
Product:
ecryptfs-utils
Reference:
DSA-2382-1
CVE-2011-1831
CVE-2011-1832
CVE-2011-1834
CVE-2011-1835
CVE-2011-1837
CVE-2011-3145
CVE    6
CVE-2011-3145
CVE-2011-1832
CVE-2011-1831
CVE-2011-1837
...
CPE    3
cpe:/o:debian:debian_linux:5.0
cpe:/o:debian:debian_linux:6.0
cpe:/a:ecryptfs:ecryptfs-utils

© SecPod Technologies