CVE-2011-1831: Medium severity ecryptfs-utils vulnerability

Published Aug 9, 2011
·
Updated

A number of flaws were reported [1] in eCryptfs that could allow a user to mount or unmount arbitrary locations, and possibly disclose confidential information:

Vasiliy Kulikov of Openwall and Dan Rosenberg discovered that eCryptfs incorrectly validated permissions on the requested mountpoint. A local attacker could use this flaw to mount to arbitrary locations, leading to privilege escalation. (CVE-2011-1831)

Vasiliy Kulikov of Openwall and Dan Rosenberg discovered that eCryptfs incorrectly validated permissions on the requested mountpoint. A local attacker could use this flaw to unmount to arbitrary locations, leading to a denial of service. (CVE-2011-1832)

Vasiliy Kulikov of Openwall and Dan Rosenberg discovered that eCryptfs incorrectly validated permissions on the requested source directory. A local attacker could use this flaw to mount an arbitrary directory, possibly leading to information disclosure. Note that this flaw also requires a fix in the kernel to be complete. (CVE-2011-1833)

Dan Rosenberg and Marc Deslauriers discovered that eCryptfs incorrectly handled modifications to the mtab file when an error occurs. A local attacker could use this flaw to corrupt the mtab file, and possibly unmount arbitrary locations, leading to a denial of service. (CVE-2011-1834)

Marc Deslauriers discovered that eCryptfs incorrectly handled keys when setting up an encrypted private directory. A local attacker could use this flaw to manipulate keys during creation of a new user. (CVE-2011-1835)

Marc Deslauriers discovered that eCryptfs incorrectly handled permissions during recovery. A local attacker could use this flaw to possibly access another user's data during the recovery process. (CVE-2011-1836)

Vasiliy Kulikov of Openwall discovered that eCryptfs incorrectly handled lock counters. A local attacker could use this flaw to possibly overwrite arbitrary files. (CVE-2011-1837)

[1] https://launchpad.net/bugs/732628

Other sources

utils/mount.ecryptfsprivate.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to effectively replace any directory with a new filesystem, and consequently gain privileges, via a mount system call.

Launchpad

Affected Software

32 affected componentsFixes available
ecryptfs ecryptfs-utils<=89
ecryptfs ecryptfs-utils=62
ecryptfs ecryptfs-utils=63
ecryptfs ecryptfs-utils=64
ecryptfs ecryptfs-utils=65
ecryptfs ecryptfs-utils=66
ecryptfs ecryptfs-utils=67
ecryptfs ecryptfs-utils=68
ecryptfs ecryptfs-utils=69
ecryptfs ecryptfs-utils=70
ecryptfs ecryptfs-utils=71
ecryptfs ecryptfs-utils=72
ecryptfs ecryptfs-utils=73
ecryptfs ecryptfs-utils=74
ecryptfs ecryptfs-utils=75
ecryptfs ecryptfs-utils=76
ecryptfs ecryptfs-utils=77
ecryptfs ecryptfs-utils=78
ecryptfs ecryptfs-utils=79
ecryptfs ecryptfs-utils=80
ecryptfs ecryptfs-utils=81
ecryptfs ecryptfs-utils=82
ecryptfs ecryptfs-utils=83
ecryptfs ecryptfs-utils=84
ecryptfs ecryptfs-utils=85
ecryptfs ecryptfs-utils=86
ecryptfs ecryptfs-utils=87
ecryptfs Ecryptfs Utils=58
ecryptfs Ecryptfs Utils=59
ecryptfs Ecryptfs Utils=60
ecryptfs Ecryptfs Utils=61
debian/ecryptfs-utils
111-5111-6111-8

Event History

Aug 9, 2011
Data Sourced
via Red Hat·08:15 PM
DescriptionSeverityAffected Software
Feb 15, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Data Sourced
via NVD·02:57 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·09:56 PM
Description
Sep 19, 2024
Data Sourced
via Ubuntu·10:41 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2011-1831?

CVE-2011-1831 has been classified with a medium severity level due to potential unauthorized access and information disclosure risks.

2

How do I fix CVE-2011-1831?

To fix CVE-2011-1831, update eCryptfs-utils to the latest version available that addresses this vulnerability.

3

Who discovered CVE-2011-1831?

CVE-2011-1831 was discovered by Vasiliy Kulikov of Openwall and Dan Rosenberg.

4

Which versions of eCryptfs-utils are affected by CVE-2011-1831?

CVE-2011-1831 affects multiple versions of eCryptfs-utils including versions 58 through 89.

5

What type of vulnerabilities does CVE-2011-1831 represent?

CVE-2011-1831 represents a flaw in permission validation in eCryptfs that could lead to unauthorized mount access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203