Description
The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly ensure that the passphrase file is created, which might allow local users to bypass intended access restrictions at a certain time in the new-user creation steps.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2382-1 | ecryptfs-utils security update |
EUVD |
EUVD-2011-1833 | The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly ensure that the passphrase file is created, which might allow local users to bypass intended access restrictions at a certain time in the new-user creation steps. |
Ubuntu USN |
USN-1188-1 | eCryptfs vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2024-08-06T22:37:25.827Z
Reserved: 2011-04-27T00:00:00.000Z
Link: CVE-2011-1835
No data.
Status : Modified
Published: 2014-02-15T14:57:06.330
Modified: 2026-04-29T01:13:23.040
Link: CVE-2011-1835
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN