mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types,...
Vulnerability Description
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-1572
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.opensuse.org/opensuse-updates/2016-01/msg00091.html
- http://www.securitytracker.com/id/1034791
- http://lists.opensuse.org/opensuse-updates/2016-01/msg00118.html
- https://bugs.launchpad.net/ecryptfs/+bug/1530566
- http://www.openwall.com/lists/oss-security/2016/01/20/6
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00004.html
- http://www.ubuntu.com/usn/USN-2876-1
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177396.html
- http://www.debian.org/security/2016/dsa-3450
- https://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/870
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177359.html
More from ecryptfs
View All →Affected Vendor
ecryptfs
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.