CVE-2011-1836
published 2014-02-15CVE-2011-1836: utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to bypass…
PriorityP414medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.38%
29.9th percentile
utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations during the recovery process.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ecryptfs-utils | < ecryptfs-utils 92-1 (bookworm) | ecryptfs-utils 92-1 (bookworm) |
| ecryptfs | ecryptfs-utils | <= 89 | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
| ecryptfs | ecryptfs-utils | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5764-q5mh-rcg7: utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to b
ghsa_unreviewed·2022-05-17
CVE-2011-1836 [MEDIUM] GHSA-5764-q5mh-rcg7: utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to b
utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations during the recovery process.
OSV
CVE-2011-1836: utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to b
osv·2014-02-15·CVSS 4.6
CVE-2011-1836 [MEDIUM] CVE-2011-1836: utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to b
utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations during the recovery process.
Red Hat
ecryptfs-utils: ecryptfs-recover-private insecure permissions on the temporary mount point
vendor_redhat·2011-08-09·CVSS 4.6
CVE-2011-1836 [MEDIUM] ecryptfs-utils: ecryptfs-recover-private insecure permissions on the temporary mount point
ecryptfs-utils: ecryptfs-recover-private insecure permissions on the temporary mount point
utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations during the recovery process.
Statement: Not vulnerable. This issue did not affect the versions of ecryptfs-utils as
shipped with Red Hat Enterprise Linux 5 or 6.
Package: ecryptfs-utils (Red Hat Enterprise Linux 5) - Not affected
Package: ecryptfs-utils (Red Hat Enterprise Linux 6) - Not affected
Ubuntu
eCryptfs vulnerabilities
vendor_ubuntu·2011-08-09·CVSS 4.6
CVE-2011-1834 [MEDIUM] eCryptfs vulnerabilities
Title: eCryptfs vulnerabilities
Summary: eCryptfs could be tricked into mounting and unmounting arbitrary locations,
and possibly disclose confidential information.
Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly
validated permissions on the requested mountpoint. A local attacker could
use this flaw to mount to arbitrary locations, leading to privilege
escalation. (CVE-2011-1831)
Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly
validated permissions on the requested mountpoint. A local attacker could
use this flaw to unmount to arbitrary locations, leading to a denial of
service. (CVE-2011-1832)
Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly
validated permissions on the requested source directory. A local attacker
cou
Debian
CVE-2011-1836: ecryptfs-utils - utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a ...
vendor_debian·2011·CVSS 4.6
CVE-2011-1836 [MEDIUM] CVE-2011-1836: ecryptfs-utils - utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a ...
utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations during the recovery process.
Scope: local
bookworm: resolved (fixed in 92-1)
bullseye: resolved (fixed in 92-1)
forky: resolved (fixed in 92-1)
sid: resolved (fixed in 92-1)
trixie: resolved (fixed in 92-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1836 ecryptfs-utils: ecryptfs-recover-private insecure permissions on the temporary mount point
bugzilla·2011-08-16·CVSS 4.6
CVE-2011-1836 [MEDIUM] CVE-2011-1836 ecryptfs-utils: ecryptfs-recover-private insecure permissions on the temporary mount point
CVE-2011-1836 ecryptfs-utils: ecryptfs-recover-private insecure permissions on the temporary mount point
Quoting Ubuntu advisory:
Marc Deslauriers discovered that eCryptfs incorrectly handled permissions during recovery. A local attacker could use this flaw to possibly access another user's data during the recovery process. This issue only applied to Ubuntu 11.04. (CVE-2011-1836)
References:
http://www.ubuntu.com/usn/usn-1188-1/
https://launchpad.net/bugs/732628
Patch is attached in the bug that track other issues from the advisory:
https://bugzilla.redhat.com/show_bug.cgi?id=729465#c4
Discussion:
As was noted in bug #729465, comment #8:
CVE-2011-1836 only affects Fedora; ecryptfs-recover-private does not exist in
ecryptfs-utils-82 (which is what is shipped with Red Hat Enterprise L
Bugzilla
CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1837 ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information
bugzilla·2011-08-09·CVSS 4.6
CVE-2011-1831 [MEDIUM] CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1837 ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information
CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1837 ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information
A number of flaws were reported [1] in eCryptfs that could allow a user to mount or unmount arbitrary locations, and possibly disclose confidential information:
Vasiliy Kulikov of Openwall and Dan Rosenberg discovered that eCryptfs incorrectly validated permissions on the requested mountpoint. A local attacker could use this flaw to mount to arbitrary locations, leading to privilege escalation. (CVE-2011-1831)
Vasiliy Kulikov of Openwall and Dan Rosenberg discovered that eCryptfs incorrectly validated permissions on the requested mountpoint. A local attacker could use this flaw to unmount to arbitrary locations,
Bugzilla
CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1836 CVE-2011-1837 ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information [fedora-
bugzilla·2011-08-09·CVSS 4.6
CVE-2011-1831 [MEDIUM] CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1836 CVE-2011-1837 ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information [fedora-
CVE-2011-1831 CVE-2011-1832 CVE-2011-1834 CVE-2011-1835 CVE-2011-1836 CVE-2011-1837 ecryptfs: multiple flaws to mount/umount arbitrary locations and possibly disclose confidential information [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update
http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00009.htmlhttp://www.ubuntu.com/usn/USN-1188-1https://bugzilla.redhat.com/show_bug.cgi?id=729465https://launchpad.net/ecryptfs/+downloadhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00009.htmlhttp://www.ubuntu.com/usn/USN-1188-1https://bugzilla.redhat.com/show_bug.cgi?id=729465https://launchpad.net/ecryptfs/+download
2014-02-15
Published