The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.
2008-11-21T02:30:00.563
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ecryptfs | ecryptfs_utils | 45 | Yes |
Application | ecryptfs | ecryptfs_utils | 46 | Yes |
Application | ecryptfs | ecryptfs_utils | 47 | Yes |
Application | ecryptfs | ecryptfs_utils | 48 | Yes |
Application | ecryptfs | ecryptfs_utils | 49 | Yes |
Application | ecryptfs | ecryptfs_utils | 50 | Yes |
Application | ecryptfs | ecryptfs_utils | 51 | Yes |
Application | ecryptfs | ecryptfs_utils | 53 | Yes |
Application | ecryptfs | ecryptfs_utils | 54 | Yes |
Application | ecryptfs | ecryptfs_utils | 55 | Yes |
Application | ecryptfs | ecryptfs_utils | 56 | Yes |
Application | ecryptfs | ecryptfs_utils | 57 | Yes |
Application | ecryptfs | ecryptfs_utils | 58 | Yes |
Application | ecryptfs | ecryptfs_utils | 59 | Yes |
Application | ecryptfs | ecryptfs_utils | 60 | Yes |
Application | ecryptfs | ecryptfs_utils | 61 | Yes |