Bug 732607 (CVE-2011-3145)

Summary: CVE-2011-3145 ecryptfs-utils: incorrect mtab group ownership
Product: [Other] Security Response Reporter: Huzaifa S. Sidhpurwala <huzaifas>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: mhlavink, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-08-03 08:30:47 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 729470, 729471, 729472, 729473    
Bug Blocks: 729476    
Attachments:
Description Flags
proposed patch none

Description Huzaifa S. Sidhpurwala 2011-08-23 05:20:06 UTC
When mount.ecrpytfs_private calls set setreuid() it doesn't also set the
effective group id. So when it creates the new version, mtab.tmp, it's
created with the group id of the user running mount.ecryptfs_private.

Reference: 
https://launchpad.net/bugs/830850

Comment 1 Huzaifa S. Sidhpurwala 2011-08-23 05:25:50 UTC
Created attachment 519393 [details]
proposed patch

Comment 3 Tomas Hoger 2011-08-24 07:26:40 UTC
Public now via Ubuntu advisory:
  http://www.ubuntu.com/usn/usn-1196-1/

Comment 6 errata-xmlrpc 2011-08-31 19:41:06 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5
  Red Hat Enterprise Linux 6

Via RHSA-2011:1241 https://rhn.redhat.com/errata/RHSA-2011-1241.html