When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version, mtab.tmp, it's created with the group id of the user running mount.ecryptfs_private.
CVSS Details
- CVSS 3.1 Base Score: 3.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ecryptfs-utilsUpgrade ecryptfs-utils-guiUpgrade ecryptfs-utils-devel | Aug 17, 2018 | Aug 23, 2011 |
| Debian | — | Upgrade ecryptfs-utils | Jul 30, 2024 | Apr 22, 2019 |
| Suse | — | Upgrade ecryptfs-utils-32bitUpgrade ecryptfs-utils | Dec 12, 2013 | Dec 10, 2013 |
| Ubuntu | — | Upgrade ecryptfs-utils | Nov 8, 2024 | Apr 22, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub