~ubuntu-branches/ubuntu/precise/ecryptfs-utils/precise-security

  • Committer: Package Import Robot
  • Author(s): Dustin Kirkland, Marc Deslauriers
  • Date: 2011-08-10 08:36:44 UTC
  • mfrom: (1.1.35 upstream)
  • Revision ID: package-import@ubuntu.com-20110810083644-04h6psjqifzbp8k4
Tags: 90-0ubuntu1
[ Marc Deslauriers ]
* SECURITY UPDATE: privilege escalation via mountpoint race conditions
  (LP: #732628)
  - debian/patches/CVE-2011-1831,1832,1834.patch: chdir into mountpoint
    before checking permissions in src/utils/mount.ecryptfs_private.c.
  - CVE-2011-1831
  - CVE-2011-1832
* SECURITY UPDATE: race condition when checking source during mount
  (LP: #732628)
  - debian/patches/CVE-2011-1833.patch: use new ecryptfs_check_dev_ruid
    kernel option when mounting directory in
    src/utils/mount.ecryptfs_private.c.
  - CVE-2011-1833
* SECURITY UPDATE: mtab corruption via improper handling (LP: #732628)
  - debian/patches/CVE-2011-1831,1832,1834.patch: modify mtab via a temp
    file first and make sure it succeeds before replacing the real mtab
    in src/utils/mount.ecryptfs_private.c.
  - CVE-2011-1834
* SECURITY UPDATE: key poisoning via insecure temp directory handling
  (LP: #732628)
  - debian/patches/CVE-2011-1835.patch: make sure we don't copy into a
    user controlled directory in src/utils/ecryptfs-setup-private.
  - CVE-2011-1835
* SECURITY UPDATE: information disclosure via recovery mount in /tmp
  (LP: #732628)
  - debian/patches/CVE-2011-1836.patch: mount inside protected
    subdirectory in src/utils/ecryptfs-recover-private.
  - CVE-2011-1836
* SECURITY UPDATE: arbitrary file overwrite via lock counter race
  condition (LP: #732628)
  - debian/patches/CVE-2011-1837.patch: verify permissions with a file
    descriptor, and don't follow symlinks in
    src/utils/mount.ecryptfs_private.c.
  - CVE-2011-1837
Filename Latest Rev Last Changed Committer Comment Size
..
debian 2 17 years ago Bazaar Package Importer * Initial release. * Repackaged upstream tarball w Diff
doc 1 17 years ago Bazaar Package Importer Import upstream version 15 Diff
m4 1.1.9 15 years ago Bazaar Package Importer Import upstream version 48 Diff
po 1.1.28 14 years ago Bazaar Package Importer Import upstream version 83 Diff
src 1 17 years ago Bazaar Package Importer Import upstream version 15 Diff
aclocal.m4 73 12 years ago Package Import Robot [ Marc Deslauriers ] * SECURITY UPDATE: privilege 64.1 KB Diff Download File
AUTHORS 34 15 years ago Bazaar Package Importer * Merge from debian unstable, remaining changes (D 535 bytes Diff Download File
ChangeLog 1.1.20 15 years ago Bazaar Package Importer Import upstream version 75 4 KB Diff Download File
File compile 1.1.28 14 years ago Bazaar Package Importer Import upstream version 83 3.6 KB Diff Download File
File config.guess 73 12 years ago Package Import Robot [ Marc Deslauriers ] * SECURITY UPDATE: privilege 43.4 KB Diff Download File
config.h.in 63 14 years ago Bazaar Package Importer [ David Planella ] * Makefile.am, configure.ac, de 3.1 KB Diff Download File
File config.sub 73 12 years ago Package Import Robot [ Marc Deslauriers ] * SECURITY UPDATE: privilege 34.3 KB Diff Download File
File configure 73 12 years ago Package Import Robot [ Marc Deslauriers ] * SECURITY UPDATE: privilege 536 KB Diff Download File
configure.ac 73 12 years ago Package Import Robot [ Marc Deslauriers ] * SECURITY UPDATE: privilege 10.3 KB Diff Download File
COPYING 1 17 years ago Bazaar Package Importer Import upstream version 15 17.5 KB Diff Download File
File depcomp 56 14 years ago Bazaar Package Importer Merged upstream release 18.1 KB Diff Download File
INSTALL 1 17 years ago Bazaar Package Importer Import upstream version 15 7.8 KB Diff Download File
File install-sh 56 14 years ago Bazaar Package Importer Merged upstream release 13.3 KB Diff Download File
File ltmain.sh 73 12 years ago Package Import Robot [ Marc Deslauriers ] * SECURITY UPDATE: privilege 276 KB Diff Download File
Makefile.am 1.1.28 14 years ago Bazaar Package Importer Import upstream version 83 1 KB Diff Download File
Makefile.in 73 12 years ago Package Import Robot [ Marc Deslauriers ] * SECURITY UPDATE: privilege 27.6 KB Diff Download File
File missing 1.1.24 14 years ago Bazaar Package Importer Import upstream version 79 11.1 KB Diff Download File
NEWS 34 15 years ago Bazaar Package Importer * Merge from debian unstable, remaining changes (D 1.1 KB Diff Download File
File py-compile 56 14 years ago Bazaar Package Importer Merged upstream release 4 KB Diff Download File
README 51 14 years ago Bazaar Package Importer [ Dustin Kirkland ] * src/utils/ecryptfs-setup-swa 12.2 KB Diff Download File
THANKS 1 17 years ago Bazaar Package Importer Import upstream version 15 601 bytes Diff Download File