CVE-2011-1835
Last modified
CVE-2011-1835 is a vulnerability of currently unknown severity. The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly ensure that the passphrase file is created, which might allow local users to bypass intended access restrictions at a certain time in the new-user creation steps.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly ensure that the passphrase file is created, which might allow local users to bypass intended access restrictions at a certain time in the new-user creation steps.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ecryptfs | Ecryptfs-Utils | <= 89 |
| Ecryptfs | Ecryptfs-Utils | 62 |
| Ecryptfs | Ecryptfs-Utils | 63 |
| Ecryptfs | Ecryptfs-Utils | 64 |
| Ecryptfs | Ecryptfs-Utils | 65 |
| Ecryptfs | Ecryptfs-Utils | 66 |
| Ecryptfs | Ecryptfs-Utils | 67 |
| Ecryptfs | Ecryptfs-Utils | 68 |
| Ecryptfs | Ecryptfs-Utils | 69 |
| Ecryptfs | Ecryptfs-Utils | 70 |
| Ecryptfs | Ecryptfs-Utils | 71 |
| Ecryptfs | Ecryptfs-Utils | 72 |
| Ecryptfs | Ecryptfs-Utils | 73 |
| Ecryptfs | Ecryptfs-Utils | 74 |
| Ecryptfs | Ecryptfs-Utils | 75 |
| Ecryptfs | Ecryptfs-Utils | 76 |
| Ecryptfs | Ecryptfs-Utils | 77 |
| Ecryptfs | Ecryptfs-Utils | 78 |
| Ecryptfs | Ecryptfs-Utils | 79 |
| Ecryptfs | Ecryptfs-Utils | 80 |
| Ecryptfs | Ecryptfs-Utils | 81 |
| Ecryptfs | Ecryptfs-Utils | 82 |
| Ecryptfs | Ecryptfs-Utils | 83 |
| Ecryptfs | Ecryptfs-Utils | 84 |
| Ecryptfs | Ecryptfs-Utils | 85 |
| Ecryptfs | Ecryptfs-Utils | 86 |
| Ecryptfs | Ecryptfs-Utils | 87 |
| Ecryptfs | Ecryptfs Utils | 58 |
| Ecryptfs | Ecryptfs Utils | 59 |
| Ecryptfs | Ecryptfs Utils | 60 |
| Ecryptfs | Ecryptfs Utils | 61 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=729465Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=729465Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-1835?
How severe is CVE-2011-1835?
How do I fix CVE-2011-1835?
Are you affected by CVE-2011-1835?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
