Ecryptfs Utils

Vendor:

First CVE: Nov 21, 2008 · Active for 17 years

12
Total CVEs
More Total CVEs than 90% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
4.7
Avg CVSS
Higher Avg CVSS than 6% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ecryptfs Utils over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 21, 2008
17 years ago
Most Recent CVE
Dec 20, 2019
2,407 days ago

CVE Severity & Scoring

Ecryptfs Utils12 CVEs
All CVEs352,101 CVEs
LowMediumHigh
Attack Vector
Local4 (33.3%)
Network0 (0.0%)
Unknown8 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (33.3%)
High0 (0.0%)
Unknown8 (66.7%)
User Interaction
None4 (33.3%)
Unknown8 (66.7%)
Required0 (0.0%)
Privileges Required
Low3 (25.0%)
High0 (0.0%)
None1 (8.3%)
Unknown8 (66.7%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesyst
Jan 22, 20168.427NONO
ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation
Dec 20, 20197.825NONO
The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords
Nov 21, 20087.218NONO
utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to bypass intended access restrict
Feb 15, 20144.617NONO
The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly ensure that the passphrase file is created, which might
Feb 15, 20144.417NONO
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to effectively replace any directory with a new
Feb 15, 20144.617NONO
eCryptfs 104 and earlier uses a default salt to encrypt the mount passphrase, which makes it easier for attackers to obtain user passwords via a brute force attack.
Mar 16, 20155.015NONO
The lock-counter implementation in utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 allows local users to overwrite arbitrary files via unspecified vectors.
Feb 15, 20143.615NONO
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly maintain the mtab file during error conditions, which allows local users to cause a denial of service (
Feb 15, 20142.113NONO
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to remove directories via a umount system call.
Feb 15, 20142.113NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Ecryptfs Utils

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8763.60.4%00
8663.60.4%00
8563.60.4%00
8463.60.4%00
8363.60.4%00
8263.60.4%00
8163.60.4%00
8063.60.4%00
7963.60.4%00
7863.60.4%00
7763.60.4%00
7663.60.4%00
7563.60.4%00
7463.60.4%00
7363.60.4%00
7263.60.4%00
7163.60.4%00
7063.60.4%00
6963.60.4%00
6863.60.4%00