LWN.net Logo

util-linux: information disclosure

Package(s):util-linux CVE #(s):CVE-2007-0822
Created:March 7, 2007 Updated:March 7, 2007
Description: Users can confuse util-linux by way of removable drives, leading to crashes and the possibility of information disclosure via the resulting core dumps.
Alerts:
Mandriva MDKSA-2007:053 2006-03-06

(Log in to post comments)

util-linux: information disclosure

Posted Mar 8, 2007 11:03 UTC (Thu) by nix (subscriber, #2304) [Link]

What sort of useful information would be exposed by *umount*? Sure it's setuid, but even so it doesn't read anything security-important, does it?

(It's still a bug, yes, but where's the security impact?)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds