USN-2876-1: eCryptfs vulnerability
20 January 2016
mount.ecryptfs_private could be used to run programs as an administrator.
Releases
Packages
- ecryptfs-utils - eCryptfs cryptographic filesystem utilities
Details
Jann Horn discovered that mount.ecryptfs_private would mount over certain
directories in the proc filesystem. A local attacker could use this to escalate
their privileges. (CVE-2016-1572)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 15.10
Ubuntu 15.04
Ubuntu 14.04
Ubuntu 12.04
In general, a standard system update will make all the necessary changes.