utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations during the recovery process.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00009.html | vendor advisory |
https://launchpad.net/ecryptfs/+download | |
https://bugzilla.redhat.com/show_bug.cgi?id=729465 | vendor advisory |
http://www.ubuntu.com/usn/USN-1188-1 | vendor advisory |