CVE-2016-1572
published 2016-01-22CVE-2016-1572: mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a…
PriorityP339high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.37%
29.1th percentile
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ecryptfs-utils | < ecryptfs-utils 106-2 (bookworm) | ecryptfs-utils 106-2 (bookworm) |
| ecryptfs | ecryptfs-utils | < 109 | 109 |
| ecryptfs | ecryptfs-utils | >= 0 < 106-2 | 106-2 |
| ecryptfs | ecryptfs-utils | >= 0 < 106-2 | 106-2 |
| ecryptfs | ecryptfs-utils | >= 0 < 106-2 | 106-2 |
| ecryptfs | ecryptfs-utils | >= 0 < 106-2 | 106-2 |
| ecryptfs | ecryptfs-utils | >= 0 < 104-0ubuntu1.14.04.4 | 104-0ubuntu1.14.04.4 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.4HIGH
vendor_debian8.4HIGH
vendor_redhat8.4HIGH
vendor_ubuntu8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
eCryptfs vulnerability
vendor_ubuntu·2016-01-20·CVSS 8.4
CVE-2016-1572 [HIGH] eCryptfs vulnerability
Title: eCryptfs vulnerability
Summary: mount.ecryptfs_private could be used to run programs as an administrator.
Jann Horn discovered that mount.ecryptfs_private would mount over certain
directories in the proc filesystem. A local attacker could use this to escalate
their privileges. (CVE-2016-1572)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ecryptfs-utils: privilege escalation by mounting over /proc/$pid
vendor_redhat·2016-01-20·CVSS 8.4
CVE-2016-1572 [HIGH] CWE-284 ecryptfs-utils: privilege escalation by mounting over /proc/$pid
ecryptfs-utils: privilege escalation by mounting over /proc/$pid
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
Package: ecryptfs-utils (Red Hat Enterprise Linux 5) - Not affected
Package: ecryptfs-utils (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2016-1572: ecryptfs-utils - mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination f...
vendor_debian·2016·CVSS 8.4
CVE-2016-1572 [HIGH] CVE-2016-1572: ecryptfs-utils - mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination f...
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
Scope: local
bookworm: resolved (fixed in 106-2)
bullseye: resolved (fixed in 106-2)
forky: resolved (fixed in 106-2)
sid: resolved (fixed in 106-2)
trixie: resolved (fixed in 106-2)
GHSA
GHSA-v495-vr49-324q: mount
ghsa_unreviewed·2022-05-13
CVE-2016-1572 [HIGH] CWE-269 GHSA-v495-vr49-324q: mount
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
OSV
CVE-2016-1572: mount
osv·2016-01-22·CVSS 8.4
CVE-2016-1572 [HIGH] CVE-2016-1572: mount
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
OSV
ecryptfs-utils vulnerability
osv·2016-01-20·CVSS 8.4
CVE-2016-1572 [HIGH] ecryptfs-utils vulnerability
ecryptfs-utils vulnerability
Jann Horn discovered that mount.ecryptfs_private would mount over certain
directories in the proc filesystem. A local attacker could use this to escalate
their privileges. (CVE-2016-1572)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9646 ikiwiki: Commit metadata forgery
bugzilla·2017-01-02·CVSS 5.0
CVE-2016-9646 [MEDIUM] CVE-2016-9646 ikiwiki: Commit metadata forgery
CVE-2016-9646 ikiwiki: Commit metadata forgery
CGI::FormBuilder->field has a context-dependent API, similar to the CGI->param API that led to Bugzilla's CVE-2014-1572. Parts of ikiwiki incorrectly called this method in list context when a scalar result, which could lead to two relatively minor attacks:
In the comments plugin, an attacker who was able to post a comment could give it a user-specified author and author-URL even if the wiki configuration did not allow for that, by crafting multiple values to other fields. Also, in the editpage plugin, an attacker who was able to edit a page could potentially forge commit authorship by crafting multiple values for the rcsinfo field.
References:
http://seclists.org/oss-sec/2016/q4/778
Discussion:
Created ikiwiki tracking bugs for this issu
Bugzilla
CVE-2016-1572 ecryptfs-utils: privilege escalation by mounting over /proc/$pid [fedora-all]
bugzilla·2016-01-21·CVSS 8.4
CVE-2016-1572 [HIGH] CVE-2016-1572 ecryptfs-utils: privilege escalation by mounting over /proc/$pid [fedora-all]
CVE-2016-1572 ecryptfs-utils: privilege escalation by mounting over /proc/$pid [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2016-1572 ecryptfs-utils: privilege escalation by mounting over /proc/$pid
bugzilla·2016-01-21·CVSS 8.4
CVE-2016-1572 [HIGH] CVE-2016-1572 ecryptfs-utils: privilege escalation by mounting over /proc/$pid
CVE-2016-1572 ecryptfs-utils: privilege escalation by mounting over /proc/$pid
An unprivileged user can mount an ecryptfs over /proc/$pid because according to stat(), it is a normal directory and owned by the user. However, the user is not actually permitted to create arbitrary directory entries in /proc/$pid, and ecryptfs' behavior might be enabling privilege escalation attacks with the help of other programs that use procfs.
Upstream bug report with reproducer:
https://bugs.launchpad.net/ecryptfs/+bug/1530566
Proposed upstream patch:
https://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/870
Discussion:
Created ecryptfs-utils tracking bugs for this issue:
Affects: fedora-all [bug 1300595]
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177359.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177396.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00118.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00004.htmlhttp://www.debian.org/security/2016/dsa-3450http://www.openwall.com/lists/oss-security/2016/01/20/6http://www.securitytracker.com/id/1034791http://www.ubuntu.com/usn/USN-2876-1https://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/870https://bugs.launchpad.net/ecryptfs/+bug/1530566http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177359.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177396.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00118.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00004.htmlhttp://www.debian.org/security/2016/dsa-3450http://www.openwall.com/lists/oss-security/2016/01/20/6http://www.securitytracker.com/id/1034791http://www.ubuntu.com/usn/USN-2876-1https://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/870https://bugs.launchpad.net/ecryptfs/+bug/1530566
2016-01-22
Published