PT-2005-1061 · None+1 · Util-Linux+1

David Watson

·

Publicado

2005-09-13

·

Atualizado

2018-10-19

·

CVE-2005-2876

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions util-linux versions 2.8 through 2.12q util-linux versions 2.13-pre1 through 2.13-pre2 Red Hat Enterprise Linux (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the util-linux package and Red Hat Enterprise Linux, which can be exploited locally to compromise the confidentiality, integrity, and availability of protected information. The exploitation can be achieved through the umount function in util-linux, allowing local users with unmount permissions to gain privileges via the -r (remount) option. This option causes the file system to be remounted with just the read-only flag, effectively clearing the nosuid, nodev, and other flags.
Recommendations For util-linux versions 2.8 through 2.12q and 2.13-pre1 through 2.13-pre2, consider disabling the -r (remount) option in the umount function to prevent privilege escalation. For Red Hat Enterprise Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-06016
BDU:2015-06017
BDU:2015-06018
BDU:2015-06019
BDU:2015-06075
CVE-2005-2876
DSA-823-1
DSA-825-1
RHSA-2005:782
RHSA-2005_782

Produtos afetados

Red Hat
Util-Linux