Vulnerability Description
mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Util-Linux | <= 2.19 |
References
- http://openwall.com/lists/oss-security/2011/03/04/10Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/04/11Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/04/12Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/04/9Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/05/3Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/05/7Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/07/9Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/14/16Third Party Advisory
- http://openwall.com/lists/oss-security/2011/03/14/5Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/14/7Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/15/6Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/22/4Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/22/6Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/31/3Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2011/03/31/4Mailing ListThird Party Advisory
FAQ
What is CVE-2011-1677?
CVE-2011-1677 is a vulnerability with a CVSS score of 4.6 (MEDIUM). mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.
How severe is CVE-2011-1677?
CVE-2011-1677 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-1677?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Util-Linux.