encryptfs-utils is vulnerable to information disclosure. A disclosure flaw was found in the way the “ecryptfs-setup-private” script passed passphrases to the “ecryptfs-wrap-passphrase” and “ecryptfs-add-passphrase” commands as command line arguments. A local user could obtain the passphrases of other users who were running the script from the process listing.
git.kernel.org/?p=linux/kernel/git/mhalcrow/ecryptfs-utils.git;a=commit;h=06de99afd53f03fe07eda0ad9d61ac6d5d4d9f53
osvdb.org/49334
osvdb.org/50353
osvdb.org/50354
osvdb.org/50355
rhn.redhat.com/errata/RHSA-2009-1307.html
secunia.com/advisories/32382
secunia.com/advisories/36552
www.openwall.com/lists/oss-security/2008/10/23/3
www.openwall.com/lists/oss-security/2008/10/29/4
www.openwall.com/lists/oss-security/2008/10/29/7
www.redhat.com/security/updates/classification/#low
access.redhat.com/errata/RHSA-2009:1307
exchange.xforce.ibmcloud.com/vulnerabilities/46073
launchpad.net/bugs/287908
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9607