PT-2007-6894 · Linux+1 · Autofs+1

Josh Lange

·

Published

2007-12-12

·

Updated

2017-09-29

·

CVE-2007-5964

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions autofs 5
Description The default configuration of autofs 5 in some Linux distributions omits the nosuid option for the hosts (/net filesystem) map. This omission allows local users to gain privileges via a setuid program on a remote NFS server.
Recommendations For autofs 5, add the nosuid option to the hosts (/net filesystem) map to prevent local users from gaining privileges via a setuid program on a remote NFS server.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5964
RHSA-2007:1128
RHSA-2007:1129
RHSA-2007_1128
RHSA-2007_1129

Affected Products

Red Hat
Autofs