mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ecryptfs-utils | Ecryptfs | * | 109 (excluding) |
Ecryptfs-utils | Ubuntu | devel | * |
Ecryptfs-utils | Ubuntu | precise | * |
Ecryptfs-utils | Ubuntu | trusty | * |
Ecryptfs-utils | Ubuntu | upstream | * |
Ecryptfs-utils | Ubuntu | vivid | * |
Ecryptfs-utils | Ubuntu | wily | * |