LWN.net Logo

pam_mount: restriction bypass

Package(s):pam_mount CVE #(s):CVE-2008-3970
Created:September 30, 2008 Updated:October 22, 2008
Description: From the Mandriva advisory: pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount.
Alerts:
Mandriva MDVSA-2008:208-1 2008-10-18
Mandriva MDVSA-2008:208 2007-09-29

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds