eCryptfs Password Information Disclosure Vulnerability
BID:31906
Info
eCryptfs Password Information Disclosure Vulnerability
| Bugtraq ID: | 31906 |
| Class: | Design Error |
| CVE: |
CVE-2008-5188 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 23 2008 12:00AM |
| Updated: | Sep 02 2009 06:42PM |
| Credit: | Jamie Strandboge |
| Vulnerable: |
Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server eCryptfs eCryptfs 0 |
| Not Vulnerable: | |
Discussion
eCryptfs Password Information Disclosure Vulnerability
eCryptfs is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
eCryptfs is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
Exploit / POC
eCryptfs Password Information Disclosure Vulnerability
Attackers can use readily available commands to exploit this issue.
Attackers can use readily available commands to exploit this issue.
Solution / Fix
eCryptfs Password Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
eCryptfs Password Information Disclosure Vulnerability
References:
References:
- eCryptfs Homepage (eCryptfs)
- eCryptfs Project Page (eCryptfs)
- Fix ecryptfs-add-passphrase and ecryptfs-wrap-passphrase (eCryptfs)
- The bash dash builtin echo apparently does not (eCryptfs)