CVE Vulnerabilities

CVE-2007-5964

Published: Dec 13, 2007 | Modified: Sep 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/net filesystem) map, which allows local users to gain privileges via a setuid program on a remote NFS server.

Affected Software

Name Vendor Start Version End Version
Enterprise_linux Redhat 5.0 (including) 5.0 (including)
Red Hat Enterprise Linux 4 RedHat autofs5-1:5.0.1-0.rc2.55.el4_6.1 *
Red Hat Enterprise Linux 5 RedHat autofs-1:5.0.1-0.rc2.55.el5.1 *

References