PT-2009-3830 · Canonical · Ecryptfs-Utils
Publicado
2009-06-09
·
Atualizado
2017-08-17
·
CVE-2009-1296
CVSS v2.0
1.9
Baixa
| Vetor | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ecryptfs-utils version 73-0ubuntu6.1
Description
The issue allows local users to potentially obtain access to the filesystem by reading log files from disk, as the mount passphrase is stored in installation logs. However, it's noted that the log files are only readable by root.
Recommendations
For ecryptfs-utils version 73-0ubuntu6.1, consider restricting access to the installation logs to prevent unauthorized users from reading the mount passphrase, even though the logs are currently only readable by root.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ecryptfs-Utils