RHSA-2011:1241: Moderate: ecryptfs-utils security update
eCryptfs is a stacked, cryptographic file system. It is transparent to theunderlying file system and provides per-file granularity. eCryptfs isreleased as a Technology Preview for Red Hat Enterprise Linux 5 and 6.The setuid mount.ecryptfsprivate utility allows users to mount an eCryptfsfile system. This utility can only be run by users in the "ecryptfs" group.A race condition flaw was found in the way mount.ecryptfsprivate checkedthe permissions of a requested mount point when mounting an encrypted filesystem. A local attacker could possibly use this flaw to escalate theirprivileges by mounting over an arbitrary directory. (CVE-2011-1831)A race condition flaw in umount.ecryptfsprivate could allow a localattacker to unmount an arbitrary file system. (CVE-2011-1832)It was found that mount.ecryptfsprivate did not handle certain errorscorrectly when updating the mtab (mounted file systems table) file,allowing a local attacker to corrupt the mtab file and possibly unmount anarbitrary file system. (CVE-2011-1834)An insecure temporary file use flaw was found in the ecryptfs-setup-privatescript. A local attacker could use this script to insert their own key thatwill subsequently be used by a new user, possibly giving the attackeraccess to the user's encrypted data if existing file permissions allowaccess. (CVE-2011-1835)A race condition flaw in mount.ecryptfsprivate could allow a localattacker to overwrite arbitrary files. (CVE-2011-1837)A race condition flaw in the way temporary files were accessed inmount.ecryptfsprivate could allow a malicious, local user to makearbitrary modifications to the mtab file. (CVE-2011-3145)A race condition flaw was found in the way mount.ecryptfsprivate checkedthe permissions of the directory to mount. A local attacker could use thisflaw to mount (and then access) a directory they would otherwise not haveaccess to. Note: The fix for this issue is incomplete until a kernel-spacechange is made. Future Red Hat Enterprise Linux 5 and 6 kernel updateswill correct this issue. (CVE-2011-1833)Red Hat would like to thank the Ubuntu Security Team for reporting theseissues. The Ubuntu Security Team acknowledges Vasiliy Kulikov of Openwalland Dan Rosenberg as the original reporters of CVE-2011-1831,CVE-2011-1832, and CVE-2011-1833; Dan Rosenberg and Marc Deslauriers as theoriginal reporters of CVE-2011-1834; Marc Deslauriers as the originalreporter of CVE-2011-1835; and Vasiliy Kulikov of Openwall as the originalreporter of CVE-2011-1837.Users of ecryptfs-utils are advised to upgrade to these updated packages,which contain backported patches to correct these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2011:1241?
The severity of RHSA-2011:1241 is classified as moderate.
How do I fix RHSA-2011:1241?
To fix RHSA-2011:1241, you should upgrade to the latest version of ecryptfs-utils, specifically 82-6.el6_1.3 or 75-5.el5_7.2 as appropriate.
Which packages are affected by RHSA-2011:1241?
The affected packages include ecryptfs-utils, ecryptfs-utils-debuginfo, ecryptfs-utils-devel, and ecryptfs-utils-python for versions up to 82-6.el6_1.3 or 75-5.el5_7.2.
Is there a workaround for RHSA-2011:1241?
There are no documented workarounds for RHSA-2011:1241, and upgrading to the patched versions is recommended.
What systems are impacted by RHSA-2011:1241?
RHSA-2011:1241 impacts systems running Red Hat Enterprise Linux 5 and 6 that utilize eCryptfs.