CVE Vulnerabilities

CVE-2007-5964

Published: Dec 13, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/net filesystem) map, which allows local users to gain privileges via a setuid program on a remote NFS server.

Affected Software

NameVendorStart VersionEnd Version
Enterprise_linuxRedhat5.0 (including)5.0 (including)
Red Hat Enterprise Linux 4RedHatautofs5-1:5.0.1-0.rc2.55.el4_6.1*
Red Hat Enterprise Linux 5RedHatautofs-1:5.0.1-0.rc2.55.el5.1*

References