CVE-2011-3145 describes a critical vulnerability in mount.ecryptfs_private versions prior to 87-0ubuntu1.2. The flaw occurs because setreuid() is called without also setting the effective group ID, leading to mtab.tmp being created with the user's group ID. This allows for a complete compromise of confidentiality, integrity, and availability, as indicated by its CVSS score of 9.8 (CRITICAL) with a network attack vector and low complexity. Despite its high severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:mount.ecrpytfs_private_project:mount.ecrpytfs_private:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.