Back to Database
Status published
Medium
CVE-2014-9687
eCryptfs 104 and earlier uses a default salt to encrypt...
Vulnerability Description
eCryptfs 104 and earlier uses a default salt to encrypt the mount passphrase, which makes it easier for attackers to obtain user passwords via a brute force attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-9687
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.opensuse.org/opensuse-updates/2016-01/msg00118.html
- http://www.openwall.com/lists/oss-security/2015/02/28/3
- http://www.openwall.com/lists/oss-security/2015/02/17/7
- http://www.openwall.com/lists/oss-security/2015/02/10/16
- https://bugs.launchpad.net/ecryptfs/+bug/906550
- http://www.ubuntu.com/usn/USN-2524-1
More from ecryptfs
View All →CVE-2016-6224
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition...
Low
3.3
CVE-2016-1572
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types,...
High
8.4
CVE-2011-1837
The lock-counter implementation in utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 allows...
Low
3.6
CVE-2011-1836
utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory...
Medium
4.6
CVE-2011-1835
The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before...
Medium
4.4
Affected Vendor
ecryptfs
View all reports →Affected Software
ecryptfs-utils
Vulnerable Versions:
0
Timeline
Official Publish:
March 16th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.