Vulnerability Description
mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain privileges by modifying this file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Scott James Remnant | Mountall | <= 2.14 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/41351Vendor Advisory
- http://www.osvdb.org/67914
- http://www.ubuntu.com/usn/USN-985-1
- http://www.vupen.com/english/advisories/2010/2342Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/mountall/+bug/591807
- http://secunia.com/advisories/41351Vendor Advisory
- http://www.osvdb.org/67914
- http://www.ubuntu.com/usn/USN-985-1
- http://www.vupen.com/english/advisories/2010/2342Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/mountall/+bug/591807
FAQ
What is CVE-2010-2961?
CVE-2010-2961 is a vulnerability with a CVSS score of 6.9 (MEDIUM). mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain privileges by modifying this file.
How severe is CVE-2010-2961?
CVE-2010-2961 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2961?
Check the references section above for vendor advisories and patch information. Affected products include: Scott James Remnant Mountall.