package: ecryptfs-utils
version: 68-1
version: 75-1
severity: serious
tags: security

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for ecryptfs-utils.

CVE-2009-1296[0]:
|Chris Jones discovered that the eCryptfs support utilities would
|report the mount passphrase into installation logs when an eCryptfs
|home directory was selected during Ubuntu installation.  The logs are
|only readable by the root user, but this still left the mount passphrase
|unencrypted on disk, potentially leading to a loss of privacy.

Please coordinate with the security team (t...@security.debian.org) to
prepare fixes for lenny.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1296
    http://security-tracker.debian.net/tracker/CVE-2009-1296



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to