7.2

CVE-2007-5191

mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KernelUtil-linux Version <= 2.13.1.1
FedoraprojectFedora Version7
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version6.10
CanonicalUbuntu Linux Version7.04
DebianDebian Linux Version3.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.243
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-252 Unchecked Return Value

The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.

http://bugs.gentoo.org/show_bug.cgi?id=195390
Third Party Advisory
Issue Tracking
http://www.securityfocus.com/bid/25973
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1018782
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=320041
Third Party Advisory
Issue Tracking