Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-prgm-j9hg-36mh

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by operating a remote NFS server and creating special device files on that server, as demonstrated by the /dev/mem device.

The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by operating a remote NFS server and creating special device files on that server, as demonstrated by the /dev/mem device.

EPSS

Процентиль: 35%
0.00138
Низкий

Связанные уязвимости

redhat
больше 17 лет назад

The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by operating a remote NFS server and creating special device files on that server, as demonstrated by the /dev/mem device.

nvd
больше 17 лет назад

The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by operating a remote NFS server and creating special device files on that server, as demonstrated by the /dev/mem device.

debian
больше 17 лет назад

The default configuration for autofs 5 (autofs5) in some Linux distrib ...

oracle-oval
больше 17 лет назад

ELSA-2007-1176: Important: autofs security update (IMPORTANT)

fstec
больше 17 лет назад

Уязвимость операционной системы Red Hat Enterprise Linux, позволяющая злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 35%
0.00138
Низкий