CVE-2012-3409: Input Validation
Published Dec 20, 2019
·Updated
ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation
Affected Software
4 affected componentsFixes available
ecryptfs ecryptfs-utils>=86<99
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/ecryptfs-utils
111-5111-6111-8
Event History
Dec 20, 2019
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
DescriptionWeakness
Feb 18, 2026
Data Sourced
via Debian·01:46 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-3409?
CVE-2012-3409 is considered a medium severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2012-3409?
To fix CVE-2012-3409, upgrade the ecryptfs-utils package to version 111-6 or later.
3
Which versions of ecryptfs-utils are affected by CVE-2012-3409?
CVE-2012-3409 affects ecryptfs-utils versions prior to 111-5 and between 86 and 99.
4
On which operating systems does CVE-2012-3409 appear?
CVE-2012-3409 has been identified in Debian GNU/Linux versions 8.0 and 9.0.
5
What actions can be taken to mitigate CVE-2012-3409?
Mitigation for CVE-2012-3409 includes restricting the usage of the suid helper to trusted users and ensuring proper filesystem options are enforced.