Vulnerability Description
When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version, mtab.tmp, it's created with the group id of the user running mount.ecryptfs_private.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mount.Ecrpytfs Private Project | Mount.Ecrpytfs Private | - |
Related Weaknesses (CWE)
References
- http://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/558PatchThird Party Advisory
- http://bazaar.launchpad.net/~ecryptfs/ecryptfs/trunk/revision/558PatchThird Party Advisory
FAQ
What is CVE-2011-3145?
CVE-2011-3145 is a vulnerability with a CVSS score of 3.8 (LOW). When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version, mtab.tmp, it's created with the group id of th...
How severe is CVE-2011-3145?
CVE-2011-3145 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-3145?
Check the references section above for vendor advisories and patch information. Affected products include: Mount.Ecrpytfs Private Project Mount.Ecrpytfs Private.