CVE-2011-1831
published 2014-02-15CVE-2011-1831: utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to effectively replace any…
PriorityP416medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.37%
28.7th percentile
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to effectively replace any directory with a new filesystem, and consequently gain privileges, via a mount system call.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ecryptfs-utils | < ecryptfs-utils 92-1 (bookworm) | ecryptfs-utils 92-1 (bookworm) |
| ecryptfs | ecryptfs-utils | <= 89 | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information
vendor_redhat·2011-08-09·CVSS 4.6
CVE-2011-1831 [MEDIUM] ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information
ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to effectively replace any directory with a new filesystem, and consequently gain privileges, via a mount system call.
Ubuntu
eCryptfs vulnerabilities
vendor_ubuntu·2011-08-09·CVSS 4.6
CVE-2011-1834 [MEDIUM] eCryptfs vulnerabilities
Title: eCryptfs vulnerabilities
Summary: eCryptfs could be tricked into mounting and unmounting arbitrary locations,
and possibly disclose confidential information.
Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly
validated permissions on the requested mountpoint. A local attacker could
use this flaw to mount to arbitrary locations, leading to privilege
escalation. (CVE-2011-1831)
Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly
validated permissions on the requested mountpoint. A local attacker could
use this flaw to unmount to arbitrary locations, leading to a denial of
service. (CVE-2011-1832)
Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly
validated permissions on the requested source directory. A local attacker
cou
Debian
CVE-2011-1831: ecryptfs-utils - utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly che...
vendor_debian·2011·CVSS 4.6
CVE-2011-1831 [MEDIUM] CVE-2011-1831: ecryptfs-utils - utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly che...
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to effectively replace any directory with a new filesystem, and consequently gain privileges, via a mount system call.
Scope: local
bookworm: resolved (fixed in 92-1)
bullseye: resolved (fixed in 92-1)
forky: resolved (fixed in 92-1)
sid: resolved (fixed in 92-1)
trixie: resolved (fixed in 92-1)
GHSA
GHSA-3699-7c24-vh7q: utils/mount
ghsa_unreviewed·2022-05-17
CVE-2011-1831 [MEDIUM] GHSA-3699-7c24-vh7q: utils/mount
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to effectively replace any directory with a new filesystem, and consequently gain privileges, via a mount system call.
OSV
CVE-2011-1831: utils/mount
osv·2014-02-15·CVSS 4.6
CVE-2011-1831 [MEDIUM] CVE-2011-1831: utils/mount
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to effectively replace any directory with a new filesystem, and consequently gain privileges, via a mount system call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1837 ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information
bugzilla·2011-08-09·CVSS 4.6
CVE-2011-1831 [MEDIUM] CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1837 ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information
CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1837 ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information
A number of flaws were reported [1] in eCryptfs that could allow a user to mount or unmount arbitrary locations, and possibly disclose confidential information:
Vasiliy Kulikov of Openwall and Dan Rosenberg discovered that eCryptfs incorrectly validated permissions on the requested mountpoint. A local attacker could use this flaw to mount to arbitrary locations, leading to privilege escalation. (CVE-2011-1831)
Vasiliy Kulikov of Openwall and Dan Rosenberg discovered that eCryptfs incorrectly validated permissions on the requested mountpoint. A local attacker could use this flaw to unmount to arbitrary locations,
Bugzilla
CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1836 CVE-2011-1837 ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information [fedora-
bugzilla·2011-08-09·CVSS 4.6
CVE-2011-1831 [MEDIUM] CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1836 CVE-2011-1837 ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information [fedora-
CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1836 CVE-2011-1837 ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update
http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00009.htmlhttp://www.ubuntu.com/usn/USN-1188-1https://bugzilla.redhat.com/show_bug.cgi?id=729465https://launchpad.net/ecryptfs/+downloadhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00009.htmlhttp://www.ubuntu.com/usn/USN-1188-1https://bugzilla.redhat.com/show_bug.cgi?id=729465https://launchpad.net/ecryptfs/+download
2014-02-15
Published