Back to search
CVE-2007-5191
Published: Oct 4, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-533-1
vendor-advisory
x_refsource_UBUNTU
https://issues.rpath.com/browse/RPL-1757
x_refsource_CONFIRM
27145
third-party-advisory
x_refsource_SECUNIA
http://bugs.gentoo.org/show_bug.cgi?id=195390
x_refsource_CONFIRM
27122
third-party-advisory
x_refsource_SECUNIA
MDKSA-2007:198
vendor-advisory
x_refsource_MANDRIVA
28349
third-party-advisory
x_refsource_SECUNIA
DSA-1449
vendor-advisory
x_refsource_DEBIAN
DSA-1450
vendor-advisory
x_refsource_DEBIAN
27104
third-party-advisory
x_refsource_SECUNIA
27283
third-party-advisory
x_refsource_SECUNIA
20080108 VMSA-2008-0001 Moderate OpenPegasus PAM Authentication Buffer Overflow and updated service console packages
mailing-list
x_refsource_BUGTRAQ
27354
third-party-advisory
x_refsource_SECUNIA
28469
third-party-advisory
x_refsource_SECUNIA
GLSA-200710-18
vendor-advisory
x_refsource_GENTOO
28348
third-party-advisory
x_refsource_SECUNIA
1018782
vdb-entry
x_refsource_SECTRACK
FEDORA-2007-2462
vendor-advisory
x_refsource_FEDORA
27687
third-party-advisory
x_refsource_SECUNIA
https://bugzilla.redhat.com/show_bug.cgi?id=320041
x_refsource_CONFIRM
28368
third-party-advisory
x_refsource_SECUNIA
27399
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:10101
vdb-entry
signature
x_refsource_OVAL
25973
vdb-entry
x_refsource_BID
27188
third-party-advisory
x_refsource_SECUNIA
http://support.avaya.com/elmodocs2/security/ASA-2008-023.htm
x_refsource_CONFIRM
ADV-2007-3417
vdb-entry
x_refsource_VUPEN
RHSA-2007:0969
vendor-advisory
x_refsource_REDHAT
SUSE-SR:2007:022
vendor-advisory
x_refsource_SUSE
http://www.vmware.com/security/advisories/VMSA-2008-0001.html
x_refsource_CONFIRM
ADV-2008-0064
vdb-entry
x_refsource_VUPEN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now