Sunday, September 12, 2010

mountall: vulnerability

Users of mountall please be advised of a vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
USN-985-1: [USN-985-1] mountall vulnerability
Details follow:



Alasdair MacGregor discovered that mountall created a udev rule file

with world-writable permissions. A local attacker could exploit this

under certain conditions to cause udev to execute arbitrary commands as

the root user.


Read more at www.criticalwatch.com
 

No comments:

Post a Comment