Login
Newsletter
Werbung

Sicherheit: Denial of Service in eCryptfs
Aktuelle Meldungen Distributionen
Name: Denial of Service in eCryptfs
ID: USN-1196-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04
Datum: Di, 23. August 2011, 17:07
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3145
Applikationen: eCryptfs

Originalnachricht


--===============7549984661343836972==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-vDxt032U/1bi0geNBQz4"


--=-vDxt032U/1bi0geNBQz4
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1196-1
August 23, 2011

ecryptfs-utils vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS

Summary:

An attacker could use eCryptfs to unmount arbitrary locations and cause a
denial of service.

Software Description:
- ecryptfs-utils: ecryptfs cryptographic filesystem (utilities)

Details:

It was discovered that eCryptfs incorrectly handled permissions when
modifying the mtab file. A local attacker could use this flaw to manipulate
the mtab file, and possibly unmount arbitrary locations, leading to a
denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
ecryptfs-utils 87-0ubuntu1.2

Ubuntu 10.10:
ecryptfs-utils 83-0ubuntu3.2.10.10.2

Ubuntu 10.04 LTS:
ecryptfs-utils 83-0ubuntu3.2.10.04.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1196-1
CVE-2011-3145

Package Information:
https://launchpad.net/ubuntu/+source/ecryptfs-utils/87-0ubuntu1.2
https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.10.2
https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.04.2



--ßDxt032U/1bi0geNBQz4
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJOU6tLAAoJEGVp2FWnRL6TFJIP/RM+Xen6lUtWQmwp9yFugsIu
kPIO36MXbY/nBWtVTwrLQS5Gpjh3MFAidR7x9/TvBVzdbGP0gJCJs6Qxw4bMrEFz
HGnS2sdfziOoKVCfK58ZPQboCklYGUDFynXCp9UiHcvBV+ayKxP+l+oUJXgXPu3T
R6zUFzAnjrb4mU1W4HFR2RYLbttuodUe8tObNZN4pZgUmcxwDWoSxryx4YoeoCrr
AQg9GG6r4txhhIczQj/5Fhvz0W6ECu8C4XAI8Wv62ceK4E4qHrS0Bt6pZNZ/EbAD
bU/XPC2uEK6Dy/rMA1tBQpVw4T5d3ECnUwJGNX6J88SYJm3t/Sab8Dk62qCnQ/va
yqVSIMYnSfK7Mqze7utehIl3x6+RokwqdvRNBCjWGL8sK7HmmcWHvNpLZU4n/OVu
zZ+mGnNvhr/QVVEzchGGQDATSRKpFcAIEwL7fAMiRsJjovhd7s6gJSZiE2ns7Xov
jtGg4/8dGnHpZnjTj1dKDUExpE4Xk+RtHtnnVfPNapGMiiYy1bs3Lg3E+70l2V7y
zL3TQczGwtLdQCPXbl2mRgx642Od7yrcVuyNhUdU+NnoR/lwWMbIxsW6LMI4QC7z
IGrLPp6oDGmQtHczskyo5HDnqUE9zquEU6LUqfOf5/YfFfH26XessKGXX84mb+p5
A4X4lnd/Fc+mEHSXEdTH
=C+rB
-----END PGP SIGNATURE-----

--=-vDxt032U/1bi0geNBQz4--



--===============7549984661343836972==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============7549984661343836972==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung