HIGH · 7.2

CVE-2007-5191

mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers...

Vulnerability Description

mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
KernelUtil-Linux<= 2.13.1.1
Loop-Aes-Utils ProjectLoop-Aes-Utils-
FedoraprojectFedora7
CanonicalUbuntu Linux6.06
DebianDebian Linux3.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-5191?

CVE-2007-5191 is a vulnerability with a CVSS score of 7.2 (HIGH). mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers...

How severe is CVE-2007-5191?

CVE-2007-5191 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-5191?

Check the references section above for vendor advisories and patch information. Affected products include: Kernel Util-Linux, Loop-Aes-Utils Project Loop-Aes-Utils, Fedoraproject Fedora, Canonical Ubuntu Linux, Debian Debian Linux.