CVE-2005-2876: High severity Andries Brouwer Util-linux vulnerability

Published Sep 13, 2005
·
Updated

umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages such as loop-aes-utils, allows local users with unmount permissions to gain privileges via the -r (remount) option, which causes the file system to be remounted with just the read-only flag, which effectively clears the nosuid, nodev, and other flags.

Affected Software

25 affected components
Andries Brouwer Util-linux=2.12a
Andries Brouwer Util-linux=2.12k
Andries Brouwer Util-linux=2.11r
Andries Brouwer Util-linux=2.10p
Andries Brouwer Util-linux=2.8.1_alpha
Andries Brouwer Util-linux=2.9i
Andries Brouwer Util-linux=2.11q
Andries Brouwer Util-linux=2.9w
Andries Brouwer Util-linux=2.11y
Andries Brouwer Util-linux=2.11x
Andries Brouwer Util-linux=2.8_12
Andries Brouwer Util-linux=2.10f
Andries Brouwer Util-linux=2.12o
Andries Brouwer Util-linux=2.12b
Andries Brouwer Util-linux=2.10m
Andries Brouwer Util-linux=2.11n
Andries Brouwer Util-linux=2.13_pre2
Andries Brouwer Util-linux=2.11z
Andries Brouwer Util-linux=2.12j
Andries Brouwer Util-linux=2.12q
Andries Brouwer Util-linux=2.13_pre1
Andries Brouwer Util-linux=2.12p
Andries Brouwer Util-linux=2.12i
Andries Brouwer Util-linux=2.11f
Andries Brouwer Util-linux=2.11w

Event History

Sep 13, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2005-2876?

CVE-2005-2876 is classified as a local privilege escalation vulnerability.

2

How do I fix CVE-2005-2876?

To fix CVE-2005-2876, upgrade util-linux to the latest version that addresses this vulnerability.

3

Which versions of util-linux are affected by CVE-2005-2876?

Versions of util-linux from 2.8 to 2.12q, including specific versions like 2.12a and 2.11r, are affected by CVE-2005-2876.

4

Can CVE-2005-2876 be exploited remotely?

No, CVE-2005-2876 requires local access for exploitation, as it affects users with unmount permissions.

5

What impact does CVE-2005-2876 have on system security?

The impact of CVE-2005-2876 allows local users to gain elevated privileges, potentially compromising system integrity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203