CVE-2014-9687: Medium severity ecryptfs ecryptfs-utils vulnerability
eCryptfs 104 and earlier uses a default salt to encrypt the mount passphrase, which makes it easier for attackers to obtain user passwords via a brute force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9687?
CVE-2014-9687 has a moderate severity level due to the potential for brute force attacks on user passwords.
How do I fix CVE-2014-9687?
To fix CVE-2014-9687, users should upgrade to eCryptfs version 105 or later where the default salt issue has been resolved.
What systems are affected by CVE-2014-9687?
CVE-2014-9687 affects eCryptfs-utils version 104 and earlier that use the default salt for encrypting mount passphrases.
Why is CVE-2014-9687 a concern for security?
CVE-2014-9687 is a concern because it allows attackers to easily obtain user passwords through brute force methods due to predictable encryption.
Is there a workaround for CVE-2014-9687?
A temporary workaround for CVE-2014-9687 could involve changing the default salt configuration, but upgrading is the recommended solution.