[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2008:208 -- Mandriva pam_mount

ID: oval:org.secpod.oval:def:301587Date: (C)2012-01-07   (M)2023-11-13
Class: PATCHFamily: unix




pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount. The updated packages have been patched to fix the issue.

Platform:
Mandriva Linux 2007.1
Mandriva Linux 2008.1
Mandriva Linux 2008.0
Product:
pam_mount
Reference:
MDVSA-2008:208
CVE-2008-3970
CVE    1
CVE-2008-3970
CPE    3
cpe:/o:mandriva:linux:2008.1
cpe:/o:mandriva:linux:2007.1
cpe:/o:mandriva:linux:2008.0

© SecPod Technologies