1.9
CVSSv2

CVE-2009-1296

Published: 09/06/2009 Updated: 17/08/2017
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The eCryptfs support utilities (ecryptfs-utils) 73-0ubuntu6.1 on Ubuntu 9.04 stores the mount passphrase in installation logs, which might allow local users to obtain access to the filesystem by reading the log files from disk. NOTE: the log files are only readable by root.

Vulnerable Product Search on Vulmon Subscribe to Product

ubuntu ubuntu 9.0.4

ubuntu 73-oubuntu 6.1

Vendor Advisories

Debian Bug report logs - #532372 ecryptfs-utils: CVE-2009-1296 unencrypted passphrase on disk Package: ecryptfs-utils; Maintainer for ecryptfs-utils is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Source for ecryptfs-utils is src:ecryptfs-utils (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmail ...
Chris Jones discovered that the eCryptfs support utilities would report the mount passphrase into installation logs when an eCryptfs home directory was selected during Ubuntu installation The logs are only readable by the root user, but this still left the mount passphrase unencrypted on disk, potentially leading to a loss of privacy ...