Vulnerability Description
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kernel | Util-Linux | <= 2.13.1.1 |
| Loop-Aes-Utils Project | Loop-Aes-Utils | - |
| Fedoraproject | Fedora | 7 |
| Canonical | Ubuntu Linux | 6.06 |
| Debian | Debian Linux | 3.1 |
Related Weaknesses (CWE)
References
- http://bugs.gentoo.org/show_bug.cgi?id=195390Issue TrackingThird Party Advisory
- http://frontal2.mandriva.com/en/security/advisories?name=MDKSA-2007:198Third Party Advisory
- http://git.kernel.org/?p=utils/util-linux-ng/util-linux-ng.git%3Ba=commit%3Bh=eb
- http://lists.opensuse.org/opensuse-security-announce/2007-10/msg00008.htmlMailing ListThird Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2008/000002.htmlThird Party Advisory
- http://secunia.com/advisories/27104Third Party Advisory
- http://secunia.com/advisories/27122Third Party Advisory
- http://secunia.com/advisories/27145Third Party Advisory
- http://secunia.com/advisories/27188Third Party Advisory
- http://secunia.com/advisories/27283Third Party Advisory
- http://secunia.com/advisories/27354Third Party Advisory
- http://secunia.com/advisories/27399Third Party Advisory
- http://secunia.com/advisories/27687Third Party Advisory
- http://secunia.com/advisories/28348Third Party Advisory
- http://secunia.com/advisories/28349Third Party Advisory
FAQ
What is CVE-2007-5191?
CVE-2007-5191 is a vulnerability with a CVSS score of 7.2 (HIGH). mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers...
How severe is CVE-2007-5191?
CVE-2007-5191 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5191?
Check the references section above for vendor advisories and patch information. Affected products include: Kernel Util-Linux, Loop-Aes-Utils Project Loop-Aes-Utils, Fedoraproject Fedora, Canonical Ubuntu Linux, Debian Debian Linux.