|Description||The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly ensure that the passphrase file is created, which might allow local users to bypass intended access restrictions at a certain time in the new-user creation steps.|
|Source||CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)|
|NVD severity||medium (attack range: local)|
Vulnerable and fixed packages
The table below lists information on source packages.
|ecryptfs-utils (PTS)||wheezy, wheezy (security)||99-1+deb7u1||fixed|
|jessie (security), jessie||103-5+deb8u1||fixed|
|buster, sid, stretch||111-4||fixed|
The information below is based on the following data on fixed versions.