CVE-2011-1836: Medium severity ecryptfs-utils vulnerability
Published Feb 15, 2014
·Updated
Last updated 24 July 2024
Other sources
utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations during the recovery process.
Affected Software
32 affected componentsFixes available
ecryptfs ecryptfs-utils<=89
ecryptfs ecryptfs-utils=62
ecryptfs ecryptfs-utils=63
ecryptfs ecryptfs-utils=64
ecryptfs ecryptfs-utils=65
ecryptfs ecryptfs-utils=66
ecryptfs ecryptfs-utils=67
ecryptfs ecryptfs-utils=68
ecryptfs ecryptfs-utils=69
ecryptfs ecryptfs-utils=70
ecryptfs ecryptfs-utils=71
ecryptfs ecryptfs-utils=72
ecryptfs ecryptfs-utils=73
ecryptfs ecryptfs-utils=74
ecryptfs ecryptfs-utils=75
ecryptfs ecryptfs-utils=76
ecryptfs ecryptfs-utils=77
ecryptfs ecryptfs-utils=78
ecryptfs ecryptfs-utils=79
ecryptfs ecryptfs-utils=80
ecryptfs ecryptfs-utils=81
ecryptfs ecryptfs-utils=82
ecryptfs ecryptfs-utils=83
ecryptfs ecryptfs-utils=84
ecryptfs ecryptfs-utils=85
ecryptfs ecryptfs-utils=86
ecryptfs ecryptfs-utils=87
ecryptfs Ecryptfs Utils=58
ecryptfs Ecryptfs Utils=59
ecryptfs Ecryptfs Utils=60
ecryptfs Ecryptfs Utils=61
debian/ecryptfs-utils
111-5111-6111-8
Event History
Feb 15, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·09:56 PM
Description
Sep 19, 2024
Data Sourced
via Ubuntu·10:41 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-1836?
CVE-2011-1836 has a medium severity level due to the potential for local users to bypass access restrictions.
2
How do I fix CVE-2011-1836?
To fix CVE-2011-1836, update ecryptfs-utils to version 90 or later.
3
Which versions of ecryptfs-utils are affected by CVE-2011-1836?
CVE-2011-1836 affects ecryptfs-utils versions prior to 90, including 58 through 89.
4
Can CVE-2011-1836 be exploited remotely?
No, CVE-2011-1836 can only be exploited locally by users with access to the system.
5
Is CVE-2011-1836 a zero-day vulnerability?
CVE-2011-1836 is not a zero-day vulnerability as it was published and addressed in 2011.