|
|
| |
|
| |
ecryptfs-utils: privilege escalation
| Package(s): | ecryptfs-utils |
CVE #(s): | CVE-2012-3409
|
| Created: | August 3, 2012 |
Updated: | August 8, 2012 |
| Description: |
From the Red Hat bugzilla:
It was reported that the private ecryptfs mount helper (/sbin/mount.ecryptfs_private), which is setuid-root, could allow an unprivileged local user to mount user-controlled ecryptfs shares on the local system. Because the ecryptfs helper does not mount filesystems with the "nosuid" and "nodev" flags, it would be possible for a user to mount a filesystem containing setuid-root binaries and/or device files that could lead to the escalation of their privileges. This could be done via a USB device, if the user had physical access to the system. |
| Alerts: |
|
( Log in to post comments)
|
|
|