CVE-2007-5191: High severity kernel util-linux vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-5191 to the following vulnerability:
mount and umount in util-linux call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
References: http://git.kernel.org/?p=utils/util-linux-ng/util-linux-ng.git;a=commit;h=ebbeb2c7ac1b00b6083905957837a271e80b187e
Other sources
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5191?
CVE-2007-5191 is considered a high-severity vulnerability due to its potential impact on system security.
How do I fix CVE-2007-5191?
To fix CVE-2007-5191, update the util-linux package to version 0:2.12a-17.el4_6.1 or later for Red Hat systems.
Which systems are affected by CVE-2007-5191?
CVE-2007-5191 affects various Linux distributions running vulnerable versions of the util-linux package.
What are the potential consequences of CVE-2007-5191?
Exploitation of CVE-2007-5191 could lead to privilege escalation, allowing unauthorized users to execute actions with elevated rights.
How can I determine if my system is vulnerable to CVE-2007-5191?
You can determine if your system is vulnerable to CVE-2007-5191 by checking the version of the util-linux package installed on your system.