Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.60241
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDVSA-2008:009 (autofs)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to autofs
announced via advisory MDVSA-2008:009.

The default behaviour of autofs 5 for the hosts map did not specify the
nosuid and nodev mount options. This could allow a local user with
control of a remote NFS server to create a setuid root executable on
the exported filesystem of the remote NFS server. If this filesystem
was mounted with the default hosts map, it would allow the user to
obtain root privileges (CVE-2007-5964). Likewise, the same scenario
would be available for local users able to create device files on
the exported filesystem which could allow the user to gain access to
important system devices (CVE-2007-6285).

Because the default behaviour of autofs was to mount -hosts map
entries with the dev and suid options enabled by default, autofs has
been altered to always use nodev and nosuid by default. In order
to have the old behaviour, the configuration must now explicitly set
the dev and/or suid options.

This change only affects the -hosts map which corresponds to the /net
entry in the default configuration.

Affected: 2007.0, 2007.1, 2008.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2008:009

Risk factor : High

CVSS Score:
6.9

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-5964
1019087
http://securitytracker.com/id?1019087
26841
http://www.securityfocus.com/bid/26841
28052
http://secunia.com/advisories/28052
28097
http://secunia.com/advisories/28097
28456
http://secunia.com/advisories/28456
40441
http://osvdb.org/40441
FEDORA-2007-4469
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00474.html
FEDORA-2007-4532
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00549.html
MDVSA-2008:009
http://www.mandriva.com/security/advisories?name=MDVSA-2008:009
RHSA-2007:1128
http://www.redhat.com/support/errata/RHSA-2007-1128.html
RHSA-2007:1129
http://www.redhat.com/support/errata/RHSA-2007-1129.html
https://bugzilla.redhat.com/show_bug.cgi?id=409701
https://bugzilla.redhat.com/show_bug.cgi?id=410031
oval:org.mitre.oval:def:10158
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10158
Common Vulnerability Exposure (CVE) ID: CVE-2007-6285
1019137
http://securitytracker.com/id?1019137
26970
http://www.securityfocus.com/bid/26970
28156
http://secunia.com/advisories/28156
28168
http://secunia.com/advisories/28168
40442
http://osvdb.org/40442
FEDORA-2007-4707
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00726.html
FEDORA-2007-4709
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00732.html
RHSA-2007:1176
http://rhn.redhat.com/errata/RHSA-2007-1176.html
RHSA-2007:1177
http://rhn.redhat.com/errata/RHSA-2007-1177.html
autofs-hostsmap-weak-securtiy(39188)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39188
https://bugzilla.redhat.com/show_bug.cgi?id=426218
oval:org.mitre.oval:def:11457
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11457
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.