ecryptfs team mailing list archive
-
ecryptfs team
-
Mailing list archive
-
Message #01817
[Bug 732628] [NEW] TOCTOU in mount.ecryptfs_private
*** This bug is a security vulnerability ***
Private security bug reported:
check_ownerships() function doesn't work as it should because of a race
condition. Arguments of both mount() and umount() calls can be changed
between the check and the usage. This may lead to arbitrary mount point
umounting or probably to gaining ability to try passphrases of
otherpeople's ecryptfs storages.
lock_counter() is also racy. It (1) tries to check existance and
ownership of the file before open(), (2) neither use stat() instead of
lstat() nor O_NOFOLLOW, (3) is not protected against deletion of the
lock file by the owner. The lock file should be probably created in root
only writable directory before dropping EUID.
** Affects: ecryptfs
Importance: Undecided
Status: New
** Affects: ecryptfs-utils (Ubuntu)
Importance: Undecided
Status: New
** Affects: ecryptfs-utils (Debian)
Importance: Undecided
Status: New
** Affects: ecryptfs-utils (Fedora)
Importance: Undecided
Status: New
** Also affects: ecryptfs-utils (Ubuntu)
Importance: Undecided
Status: New
** Also affects: ecryptfs-utils (Fedora)
Importance: Undecided
Status: New
** Also affects: ecryptfs-utils (Debian)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of eCryptfs,
which is a direct subscriber.
https://bugs.launchpad.net/bugs/732628
Title:
TOCTOU in mount.ecryptfs_private
Status in eCryptfs - Enterprise Cryptographic Filesystem:
New
Status in “ecryptfs-utils” package in Ubuntu:
New
Status in “ecryptfs-utils” package in Debian:
New
Status in “ecryptfs-utils” package in Fedora:
New
Bug description:
check_ownerships() function doesn't work as it should because of a
race condition. Arguments of both mount() and umount() calls can be
changed between the check and the usage. This may lead to arbitrary
mount point umounting or probably to gaining ability to try
passphrases of otherpeople's ecryptfs storages.
lock_counter() is also racy. It (1) tries to check existance and
ownership of the file before open(), (2) neither use stat() instead of
lstat() nor O_NOFOLLOW, (3) is not protected against deletion of the
lock file by the owner. The lock file should be probably created in
root only writable directory before dropping EUID.
Follow ups
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-11-08
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Marc Deslauriers, 2011-10-25
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-10-25
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-10-25
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-10-25
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-10-20
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-10-20
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-10-11
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-09-29
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-09-29
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-09-23
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Jamie Strandboge, 2011-09-21
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Jamie Strandboge, 2011-09-21
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Jamie Strandboge, 2011-09-21
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-09-21
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-09-21
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Andy Whitcroft, 2011-09-20
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Ubuntu QA's Bug Bot, 2011-09-14
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-09-13
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-09-13
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Dustin Kirkland, 2011-09-01
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-09-01
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Herton R. Krzesinski, 2011-08-31
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-08-24
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Kees Cook, 2011-08-16
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-08-12
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Tim Gardner, 2011-08-11
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Kees Cook, 2011-08-10
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Kees Cook, 2011-08-10
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Kees Cook, 2011-08-10
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Marc Deslauriers, 2011-08-09
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-08-09
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-08-09
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-08-09
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-08-09
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-08-09
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: segooon, 2011-07-27
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Kees Cook, 2011-07-27
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Marc Deslauriers, 2011-07-27
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Marc Deslauriers, 2011-07-12
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Dan Rosenberg, 2011-07-12
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Dan Rosenberg, 2011-07-09
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Marc Deslauriers, 2011-07-09
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Dan Rosenberg, 2011-07-09
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-05-24
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-05-24
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Launchpad Bug Tracker, 2011-05-24
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Marc Deslauriers, 2011-03-19
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Marc Deslauriers, 2011-03-18
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Dustin Kirkland, 2011-03-18
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Dustin Kirkland, 2011-03-18
-
[Bug 732628] Re: TOCTOU in mount.ecryptfs_private
From: Dustin Kirkland, 2011-03-18
-
[Bug 732628] [NEW] TOCTOU in mount.ecryptfs_private
From: segooon, 2011-03-10
References