CVE Vulnerabilities

CVE-2007-6285

Published: Dec 20, 2007 | Modified: Sep 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.2 MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access important devices by operating a remote NFS server and creating special device files on that server, as demonstrated by the /dev/mem device.

Affected Software

Name Vendor Start Version End Version
Enterprise_linux Redhat 4.0 (including) 4.0 (including)
Enterprise_linux Redhat 5.0 (including) 5.0 (including)
Red Hat Enterprise Linux 4 RedHat autofs5-1:5.0.1-0.rc2.55.el4_6.2 *
Red Hat Enterprise Linux 5 RedHat autofs-1:5.0.1-0.rc2.55.el5.2 *

References