LWN.net Logo

ecryptfs-utils: passphrase leak

Package(s):ecryptfs-utils CVE #(s):CVE-2009-1296
Created:June 9, 2009 Updated:September 16, 2009
Description: From the Ubuntu advisory: Chris Jones discovered that the eCryptfs support utilities would report the mount passphrase into installation logs when an eCryptfs home directory was selected during Ubuntu installation. The logs are only readable by the root user, but this still left the mount passphrase unencrypted on disk, potentially leading to a loss of privacy.
Alerts:
CentOS CESA-2009:1307 2009-09-15
Red Hat RHSA-2009:1307-02 2009-09-02
Ubuntu USN-783-1 2009-06-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds