CVE-2011-1835: Medium severity ecryptfs-utils vulnerability
Published Feb 15, 2014
·Updated
Last updated 24 July 2024
Other sources
The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly ensure that the passphrase file is created, which might allow local users to bypass intended access restrictions at a certain time in the new-user creation steps.
Affected Software
32 affected componentsFixes available
ecryptfs ecryptfs-utils=68
ecryptfs ecryptfs-utils=62
ecryptfs ecryptfs-utils=74
ecryptfs ecryptfs-utils=87
ecryptfs ecryptfs-utils=82
ecryptfs ecryptfs-utils=86
ecryptfs ecryptfs-utils=80
ecryptfs ecryptfs-utils=65
ecryptfs ecryptfs-utils=79
ecryptfs ecryptfs-utils=83
ecryptfs ecryptfs-utils=72
ecryptfs ecryptfs-utils=69
ecryptfs ecryptfs-utils=63
ecryptfs ecryptfs-utils=64
ecryptfs Ecryptfs Utils=60
ecryptfs Ecryptfs Utils=58
ecryptfs ecryptfs-utils=70
ecryptfs ecryptfs-utils=77
ecryptfs Ecryptfs Utils=61
ecryptfs ecryptfs-utils=76
ecryptfs ecryptfs-utils=75
ecryptfs ecryptfs-utils=71
ecryptfs ecryptfs-utils=85
ecryptfs ecryptfs-utils=78
ecryptfs ecryptfs-utils<=89
ecryptfs ecryptfs-utils=84
ecryptfs ecryptfs-utils=67
ecryptfs ecryptfs-utils=81
ecryptfs ecryptfs-utils=73
ecryptfs ecryptfs-utils=66
ecryptfs Ecryptfs Utils=59
debian/ecryptfs-utils
111-5111-6111-8
Event History
Feb 15, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·09:56 PM
Description
Sep 19, 2024
Data Sourced
via Ubuntu·10:41 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-1835?
CVE-2011-1835 is considered to have a moderate severity level due to the potential for local users to bypass access restrictions.
2
How do I fix CVE-2011-1835?
To fix CVE-2011-1835, you should upgrade to ecryptfs-utils version 90 or later.
3
What versions of ecryptfs-utils are affected by CVE-2011-1835?
CVE-2011-1835 affects ecryptfs-utils versions 89 and earlier.
4
Is my system vulnerable to CVE-2011-1835 if I am using ecryptfs-utils version 88?
Yes, using ecryptfs-utils version 88 means your system is vulnerable to CVE-2011-1835.
5
Can CVE-2011-1835 be exploited remotely?
CVE-2011-1835 cannot be exploited remotely; it requires local access.