The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2008/10/23/3 | mailing list |
http://www.openwall.com/lists/oss-security/2008/10/29/7 | mailing list |
https://launchpad.net/bugs/287908 | |
http://git.kernel.org/?p=linux/kernel/git/mhalcrow/ecryptfs-utils.git%3Ba=commit%3Bh=06de99afd53f03fe07eda0ad9d61ac6d5d4d9f53 | |
http://osvdb.org/50355 | vdb entry |
http://www.openwall.com/lists/oss-security/2008/10/29/4 | mailing list |
http://secunia.com/advisories/32382 | third party advisory |
http://osvdb.org/50354 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46073 | vdb entry |
http://osvdb.org/49334 | vdb entry |
http://rhn.redhat.com/errata/RHSA-2009-1307.html | vendor advisory |
http://secunia.com/advisories/36552 | third party advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9607 | vdb entry signature |
http://osvdb.org/50353 | vdb entry |