Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-6285
Description:The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by operating a remote NFS server and creating special device files on that server, as demonstrated by the /dev/mem device.
Test IDs: 1.3.6.1.4.1.25623.1.0.122621   1.3.6.1.4.1.25623.1.0.60058  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-6285
1019137
http://securitytracker.com/id?1019137
26970
http://www.securityfocus.com/bid/26970
28156
http://secunia.com/advisories/28156
28168
http://secunia.com/advisories/28168
28456
http://secunia.com/advisories/28456
40442
http://osvdb.org/40442
FEDORA-2007-4707
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00726.html
FEDORA-2007-4709
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00732.html
MDVSA-2008:009
http://www.mandriva.com/security/advisories?name=MDVSA-2008:009
RHSA-2007:1176
http://rhn.redhat.com/errata/RHSA-2007-1176.html
RHSA-2007:1177
http://rhn.redhat.com/errata/RHSA-2007-1177.html
autofs-hostsmap-weak-securtiy(39188)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39188
https://bugzilla.redhat.com/show_bug.cgi?id=426218
https://bugzilla.redhat.com/show_bug.cgi?id=426218
oval:org.mitre.oval:def:11457
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11457




© 1998-2025 E-Soft Inc. All rights reserved.