LWN.net Logo

pmount: insecure temporary file

Package(s):pmount CVE #(s):CVE-2010-2192
Created:June 18, 2010 Updated:June 23, 2010
Description: From the Debian advisory:

Dan Rosenberg discovered that pmount, a wrapper around the standard mount program which permits normal users to mount removable devices without a matching /etc/fstab entry, creates files in /var/lock insecurely. A local attacker could overwrite arbitrary files utilising a symlink attack.

Alerts:
Debian DSA-2063-1 2010-06-17

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds