6.9

CVE-2008-3970

pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pam MountPam Mount Version0.10
Pam MountPam Mount Version0.11
Pam MountPam Mount Version0.12.2
Pam MountPam Mount Version0.13
Pam MountPam Mount Version0.15
Pam MountPam Mount Version0.16
Pam MountPam Mount Version0.17
Pam MountPam Mount Version0.18
Pam MountPam Mount Version0.19
Pam MountPam Mount Version0.20
Pam MountPam Mount Version0.21
Pam MountPam Mount Version0.26
Pam MountPam Mount Version0.27
Pam MountPam Mount Version0.28
Pam MountPam Mount Version0.29
Pam MountPam Mount Version0.31
Pam MountPam Mount Version0.32
Pam MountPam Mount Version0.35
Pam MountPam Mount Version0.35.1
Pam MountPam Mount Version0.37
Pam MountPam Mount Version0.38
Pam MountPam Mount Version0.39
Pam MountPam Mount Version0.40
Pam MountPam Mount Version0.41
Pam MountPam Mount Version0.43
Pam MountPam Mount Version0.44
Pam MountPam Mount Version0.45
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.235
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.html
http://dev.medozas.de/gitweb.cgi?p=pam_mount%3Ba=commitdiff%3Bh=33b91d7659ae3aa78b1e94fd3f8e545ae5ff25db
http://sourceforge.net/mailarchive/forum.php?thread_name=alpine.LNX.1.10.0809042353120.17569%40fbirervta.pbzchgretzou.qr&forum_name=pam-mount-user
http://sourceforge.net/project/shownotes.php?release_id=624240
http://www.mandriva.com/security/advisories?name=MDVSA-2008:208
http://www.openwall.com/lists/oss-security/2008/09/06/3
http://www.openwall.com/lists/oss-security/2008/09/09/12
http://www.securityfocus.com/bid/31041
https://exchange.xforce.ibmcloud.com/vulnerabilities/44960