CVE-2011-3145
published 2019-04-22CVE-2011-3145: When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version…
PriorityP336critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
0.98%
58.1th percentile
When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version, mtab.tmp, it's created with the group id of the user running mount.ecryptfs_private.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ecryptfs-utils | < ecryptfs-utils 92-1 (bookworm) | ecryptfs-utils 92-1 (bookworm) |
| ecryptfs | ecryptfs-utils | >= 0 < 92-1 | 92-1 |
| ecryptfs | ecryptfs-utils | >= 0 < 92-1 | 92-1 |
| ecryptfs | ecryptfs-utils | >= 0 < 92-1 | 92-1 |
| ecryptfs | ecryptfs-utils | >= 0 < 92-1 | 92-1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian3.8LOW
vendor_redhat3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ecryptfs-utils: incorrect mtab group ownership
vendor_redhat·2011-08-23·CVSS 3.8
CVE-2011-3145 [LOW] ecryptfs-utils: incorrect mtab group ownership
ecryptfs-utils: incorrect mtab group ownership
When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version, mtab.tmp, it's created with the group id of the user running mount.ecryptfs_private.
Ubuntu
eCryptfs vulnerability
vendor_ubuntu·2011-08-23
CVE-2011-3145 eCryptfs vulnerability
Title: eCryptfs vulnerability
Summary: An attacker could use eCryptfs to unmount arbitrary locations and cause a
denial of service.
It was discovered that eCryptfs incorrectly handled permissions when
modifying the mtab file. A local attacker could use this flaw to manipulate
the mtab file, and possibly unmount arbitrary locations, leading to a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2011-3145: ecryptfs-utils - When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doe...
vendor_debian·2011·CVSS 3.8
CVE-2011-3145 [LOW] CVE-2011-3145: ecryptfs-utils - When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doe...
When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version, mtab.tmp, it's created with the group id of the user running mount.ecryptfs_private.
Scope: local
bookworm: resolved (fixed in 92-1)
bullseye: resolved (fixed in 92-1)
forky: resolved (fixed in 92-1)
sid: resolved (fixed in 92-1)
trixie: resolved (fixed in 92-1)
GHSA
GHSA-r6pf-mxwq-6rrh: When mount
ghsa_unreviewed·2022-04-22
CVE-2011-3145 [CRITICAL] GHSA-r6pf-mxwq-6rrh: When mount
When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version, mtab.tmp, it's created with the group id of the user running mount.ecryptfs_private.
OSV
CVE-2011-3145: When mount
osv·2019-04-22·CVSS 9.8
CVE-2011-3145 [CRITICAL] CVE-2011-3145: When mount
When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version, mtab.tmp, it's created with the group id of the user running mount.ecryptfs_private.
No detection rules found.
No public exploits indexed.
arXiv
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
arxiv_fulltext·2022-09-26
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
Meghna Pancholi
[email protected]
Columbia University
Andreas D. Kellas
[email protected]
Columbia University
Vasileios P. Kemerlis
[email protected]
Brown University
Simha Sethumadhavan
[email protected]
Columbia University
## Abstract
We introduce , a novel technique for automatically learning system
call filtering policies for containerized microservices applications. At
run-time, automatically learns which system calls a program should
be allowed to invoke, while rejecting attempts to call spurious system calls.
Further, addresses many of the shortcomings of state-of-the-art
static analysis-based techniques, such as the ability to generate tight filters
for programs written in interpreted languages such as PHP, Python, and
JavaScript. has a simple and rob
Bugzilla
CVE-2011-3145 ecryptfs-utils: incorrect mtab group ownership
bugzilla·2011-08-23·CVSS 3.8
CVE-2011-3145 [LOW] CVE-2011-3145 ecryptfs-utils: incorrect mtab group ownership
CVE-2011-3145 ecryptfs-utils: incorrect mtab group ownership
When mount.ecrpytfs_private calls set setreuid() it doesn't also set the
effective group id. So when it creates the new version, mtab.tmp, it's
created with the group id of the user running mount.ecryptfs_private.
Reference:
https://launchpad.net/bugs/830850
Discussion:
Created attachment 519393
proposed patch
---
Public now via Ubuntu advisory:
http://www.ubuntu.com/usn/usn-1196-1/
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2011:1241 https://rhn.redhat.com/errata/RHSA-2011-1241.html
2019-04-22
Published