{"api_version":"1","generated_at":"2026-07-24T20:41:22+00:00","cve":"CVE-2009-1296","urls":{"html":"https://cve.report/CVE-2009-1296","api":"https://cve.report/api/cve/CVE-2009-1296.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-1296","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-1296"},"summary":{"title":"CVE-2009-1296","description":"The eCryptfs support utilities (ecryptfs-utils) 73-0ubuntu6.1 on Ubuntu 9.04 stores the mount passphrase in installation logs, which might allow local users to obtain access to the filesystem by reading the log files from disk.  NOTE: the log files are only readable by root.","state":"PUBLISHED","assigner":"canonical","published_at":"2009-06-09 20:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"1.9","severity":"","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:N/A:N","baseScore":1.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.ubuntu.com/usn/usn-783-1","name":"http://www.ubuntu.com/usn/usn-783-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"USN-783-1: eCryptfs vulnerability | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/51191","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/51191","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1022347","name":"http://www.securitytracker.com/id?1022347","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - eCryptfs Writes the Mount Passphrase to Log Files","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/35383","name":"http://secunia.com/advisories/35383","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA35383 - Ubuntu update for ecryptfs-utils - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-1296","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1296","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"1296","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ubuntu","cpe5":"73-oubuntu","cpe6":"6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1296","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ubuntu","cpe5":"ubuntu","cpe6":"9.0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2009-1296","organization":"Red Hat","lastmodified":"2009-06-10","contributor":"Tomas Hoger","statementText":"Not vulnerable. This issue did not affect the versions of ecryptfs-utils as shipped with Red Hat Enterprise Linux 5. eCryptfs encrypted home directories are not set up during the system installation, so theres no possibility for leaking encryption passwords to the installation log file.","cve_year":"2009","cve_id":"1296","crc32":"ed6e870d"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:04:49.427Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"35383","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35383"},{"name":"USN-783-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-783-1"},{"name":"1022347","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1022347"},{"name":"ecryptfs-passphrase-info-disclosure(51191)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/51191"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-06-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"The eCryptfs support utilities (ecryptfs-utils) 73-0ubuntu6.1 on Ubuntu 9.04 stores the mount passphrase in installation logs, which might allow local users to obtain access to the filesystem by reading the log files from disk.  NOTE: the log files are only readable by root."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"cc1ad9ee-3454-478d-9317-d3e869d708bc","shortName":"canonical"},"references":[{"name":"35383","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35383"},{"name":"USN-783-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/usn-783-1"},{"name":"1022347","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1022347"},{"name":"ecryptfs-passphrase-info-disclosure(51191)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/51191"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@ubuntu.com","ID":"CVE-2009-1296","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The eCryptfs support utilities (ecryptfs-utils) 73-0ubuntu6.1 on Ubuntu 9.04 stores the mount passphrase in installation logs, which might allow local users to obtain access to the filesystem by reading the log files from disk.  NOTE: the log files are only readable by root."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"35383","refsource":"SECUNIA","url":"http://secunia.com/advisories/35383"},{"name":"USN-783-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/usn-783-1"},{"name":"1022347","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1022347"},{"name":"ecryptfs-passphrase-info-disclosure(51191)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/51191"}]}}}},"cveMetadata":{"assignerOrgId":"cc1ad9ee-3454-478d-9317-d3e869d708bc","assignerShortName":"canonical","cveId":"CVE-2009-1296","datePublished":"2009-06-09T20:00:00.000Z","dateReserved":"2009-04-15T00:00:00.000Z","dateUpdated":"2024-08-07T05:04:49.427Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-06-09 20:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:N/A:N","baseScore":1.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.4,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ubuntu:73-oubuntu:6.1:*:*:*:*:*:*:*","matchCriteriaId":"8F6E6F4C-968E-475C-9BF1-4D34ABBA8BE1"},{"vulnerable":true,"criteria":"cpe:2.3:o:ubuntu:ubuntu:9.0.4:*:*:*:*:*:*:*","matchCriteriaId":"24066D17-EE95-4E06-9FAC-DA9B2227195F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"1296","Ordinal":"1","Title":"CVE-2009-1296","CVE":"CVE-2009-1296","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"1296","Ordinal":"1","NoteData":"The eCryptfs support utilities (ecryptfs-utils) 73-0ubuntu6.1 on Ubuntu 9.04 stores the mount passphrase in installation logs, which might allow local users to obtain access to the filesystem by reading the log files from disk.  NOTE: the log files are only readable by root.","Type":"Description","Title":"CVE-2009-1296"},{"CveYear":"2009","CveId":"1296","Ordinal":"2","NoteData":"2009-06-09","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"1296","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}