Your submission was sent successfully! Close

CVE-2011-1835

Published: 9 August 2011

The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly ensure that the passphrase file is created, which might allow local users to bypass intended access restrictions at a certain time in the new-user creation steps.

Priority

Medium

Status

Package Release Status
ecryptfs-utils
Launchpad, Ubuntu, Debian
hardy Not vulnerable
(code not present)
lucid
Released (83-0ubuntu3.2.10.04.1)
maverick
Released (83-0ubuntu3.2.10.10.1)
natty
Released (87-0ubuntu1.1)
upstream Needs triage