CVE Vulnerabilities

CVE-2008-3970

Published: Sep 11, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount.

Affected Software

NameVendorStart VersionEnd Version
Pam_mountPam_mount0.10 (including)0.10 (including)
Pam_mountPam_mount0.11 (including)0.11 (including)
Pam_mountPam_mount0.12.2 (including)0.12.2 (including)
Pam_mountPam_mount0.13 (including)0.13 (including)
Pam_mountPam_mount0.15 (including)0.15 (including)
Pam_mountPam_mount0.16 (including)0.16 (including)
Pam_mountPam_mount0.17 (including)0.17 (including)
Pam_mountPam_mount0.18 (including)0.18 (including)
Pam_mountPam_mount0.19 (including)0.19 (including)
Pam_mountPam_mount0.20 (including)0.20 (including)
Pam_mountPam_mount0.21 (including)0.21 (including)
Pam_mountPam_mount0.26 (including)0.26 (including)
Pam_mountPam_mount0.27 (including)0.27 (including)
Pam_mountPam_mount0.28 (including)0.28 (including)
Pam_mountPam_mount0.29 (including)0.29 (including)
Pam_mountPam_mount0.31 (including)0.31 (including)
Pam_mountPam_mount0.32 (including)0.32 (including)
Pam_mountPam_mount0.35 (including)0.35 (including)
Pam_mountPam_mount0.35.1 (including)0.35.1 (including)
Pam_mountPam_mount0.37 (including)0.37 (including)
Pam_mountPam_mount0.38 (including)0.38 (including)
Pam_mountPam_mount0.39 (including)0.39 (including)
Pam_mountPam_mount0.40 (including)0.40 (including)
Pam_mountPam_mount0.41 (including)0.41 (including)
Pam_mountPam_mount0.43 (including)0.43 (including)
Pam_mountPam_mount0.44 (including)0.44 (including)
Pam_mountPam_mount0.45 (including)0.45 (including)
Libpam-mountUbuntudapper*
Libpam-mountUbuntufeisty*
Libpam-mountUbuntugutsy*
Libpam-mountUbuntuhardy*
Libpam-mountUbuntuintrepid*
Libpam-mountUbuntuupstream*

References