CVE-2011-1835

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
15/02/2014
Last modified:
11/04/2025

Description

The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly ensure that the passphrase file is created, which might allow local users to bypass intended access restrictions at a certain time in the new-user creation steps.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ecryptfs:ecryptfs-utils:*:*:*:*:*:*:*:* 89 (including)
cpe:2.3:a:ecryptfs:ecryptfs-utils:62:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs-utils:63:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs-utils:64:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs-utils:65:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs-utils:66:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs-utils:67:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs-utils:68:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs-utils:69:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs-utils:70:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs-utils:71:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs-utils:72:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs-utils:73:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs-utils:74:*:*:*:*:*:*:*
cpe:2.3:a:ecryptfs:ecryptfs-utils:75:*:*:*:*:*:*:*