First published: Wed Dec 19 2007(Updated: )
It was reported to secalert that the autofs defaults do not set the nodev NFS option. <a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED ERRATA - CVE-2007-5964 autofs defaults don't restrict suid in /net" href="show_bug.cgi?id=410031">bug 410031</a> notes the missing nosuid option by default for the /net autofs filesystems, the fix for that issue did not take into account that there was also a missing nodev option for these filesystems. Without the nodev option, it is possible for an attacker to mount a remote filesystem which could give them access to various devices that should normally have restricted access, such as /dev/mem, and various hardware devices. Acknowledgements: Red Hat would like to thank Tim Baum for reporting this issue.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Enterprise Linux | =4.0 | |
Redhat Enterprise Linux | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.