PT-2009-3830 · Canonical · Ecryptfs-Utils

Published

2009-06-09

·

Updated

2017-08-17

·

CVE-2009-1296

CVSS v2.0

1.9

Low

VectorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ecryptfs-utils version 73-0ubuntu6.1
Description The issue allows local users to potentially obtain access to the filesystem by reading log files from disk, as the mount passphrase is stored in installation logs. However, it's noted that the log files are only readable by root.
Recommendations For ecryptfs-utils version 73-0ubuntu6.1, consider restricting access to the installation logs to prevent unauthorized users from reading the mount passphrase, even though the logs are currently only readable by root.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1296

Affected Products

Ecryptfs-Utils