LWN.net Logo

ecryptfs-utils: privilege escalation

Package(s):ecryptfs-utils CVE #(s):CVE-2012-3409
Created:August 3, 2012 Updated:August 8, 2012
Description: From the Red Hat bugzilla:

It was reported that the private ecryptfs mount helper (/sbin/mount.ecryptfs_private), which is setuid-root, could allow an unprivileged local user to mount user-controlled ecryptfs shares on the local system. Because the ecryptfs helper does not mount filesystems with the "nosuid" and "nodev" flags, it would be possible for a user to mount a filesystem containing setuid-root binaries and/or device files that could lead to the escalation of their privileges. This could be done via a USB device, if the user had physical access to the system.

Alerts:
Fedora FEDORA-2012-11069 2012-08-03
Fedora FEDORA-2012-11049 2012-08-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds