Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2011-1835


The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly ensure that the passphrase file is created, which might allow local users to bypass intended access restrictions at a certain time in the new-user creation steps.


Published

2014-02-15T14:57:06.330

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.4 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.4

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-255

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ecryptfs ecryptfs-utils ≤ 89 Yes
Application ecryptfs ecryptfs-utils 62 Yes
Application ecryptfs ecryptfs-utils 63 Yes
Application ecryptfs ecryptfs-utils 64 Yes
Application ecryptfs ecryptfs-utils 65 Yes
Application ecryptfs ecryptfs-utils 66 Yes
Application ecryptfs ecryptfs-utils 67 Yes
Application ecryptfs ecryptfs-utils 68 Yes
Application ecryptfs ecryptfs-utils 69 Yes
Application ecryptfs ecryptfs-utils 70 Yes
Application ecryptfs ecryptfs-utils 71 Yes
Application ecryptfs ecryptfs-utils 72 Yes
Application ecryptfs ecryptfs-utils 73 Yes
Application ecryptfs ecryptfs-utils 74 Yes
Application ecryptfs ecryptfs-utils 75 Yes
Application ecryptfs ecryptfs-utils 76 Yes
Application ecryptfs ecryptfs-utils 77 Yes
Application ecryptfs ecryptfs-utils 78 Yes
Application ecryptfs ecryptfs-utils 79 Yes
Application ecryptfs ecryptfs-utils 80 Yes
Application ecryptfs ecryptfs-utils 81 Yes
Application ecryptfs ecryptfs-utils 82 Yes
Application ecryptfs ecryptfs-utils 83 Yes
Application ecryptfs ecryptfs-utils 84 Yes
Application ecryptfs ecryptfs-utils 85 Yes
Application ecryptfs ecryptfs-utils 86 Yes
Application ecryptfs ecryptfs-utils 87 Yes
Application ecryptfs ecryptfs_utils 58 Yes
Application ecryptfs ecryptfs_utils 59 Yes
Application ecryptfs ecryptfs_utils 60 Yes
Application ecryptfs ecryptfs_utils 61 Yes

References