CVE-2008-3970

pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pam_mount:pam_mount:0.10:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.11:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.12.2:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.13:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.15:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.16:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.17:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.18:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.19:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.20:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.21:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.26:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.27:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.28:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.29:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.31:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.32:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.35:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.35.1:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.37:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.38:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.39:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.40:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.41:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.43:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.44:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.45:*:*:*:*:*:*:*

History

07 Nov 2023, 02:02

Type Values Removed Values Added
References
  • {'url': 'http://dev.medozas.de/gitweb.cgi?p=pam_mount;a=commitdiff;h=33b91d7659ae3aa78b1e94fd3f8e545ae5ff25db', 'name': 'http://dev.medozas.de/gitweb.cgi?p=pam_mount;a=commitdiff;h=33b91d7659ae3aa78b1e94fd3f8e545ae5ff25db', 'tags': [], 'refsource': 'CONFIRM'}
  • () http://dev.medozas.de/gitweb.cgi?p=pam_mount%3Ba=commitdiff%3Bh=33b91d7659ae3aa78b1e94fd3f8e545ae5ff25db -

Information

Published : 2008-09-11 01:13

Updated : 2024-02-28 11:21


NVD link : CVE-2008-3970

Mitre link : CVE-2008-3970

CVE.ORG link : CVE-2008-3970


JSON object : View

Products Affected

pam_mount

  • pam_mount
CWE
CWE-264

Permissions, Privileges, and Access Controls