CVE-2010-0296: Input Validation

Published Jan 28, 2010
·
Updated

It was found that glibc's utility, responsible for editing of system's mtab table, improperly sanitized user supplied mount point names containing certain special character. Local attacker could use this flaw to add arbitrary mount points (corrupt system's "/etc/mtab" file) or, potentially, set unauthorized mount options. Other attacks are also possible.

Issue severity note: ------------------- The /etc/mtab file handles mounted devices and is automatically updated by the mount command (more precisely by the dedicated "mount" tool for relevant filesystem). Unprivileged user to be able to run such a tool (and modify content of /etc/mtab), this tool needs to be suid root enabled. The dedicated "mount" tools, as shipped with Red Hat Enterprise Linux (mount.cifs, mount.fuse, fusermount, mount.nfs, mount.nfs4) does NOT allow unprivileged user to use them (without prior grant of additional privileges from the privileged user) for editing of system's /etc/mtab file, which mitigates impact of this flaw.

Other sources

The encodename macro in misc/mntentr.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.

Red Hat

Affected Software

40 affected componentsFixes available
redhat/glibc<0:2.5-58.el5_6.2
0:2.5-58.el5_6.2
GNU glibc=2.2.2
GNU glibc=2.9
GNU glibc=2.7
GNU glibc=2.1.2
GNU glibc=2.11
GNU glibc=2.0.5
GNU glibc=2.2.5
GNU glibc=2.0.6
GNU glibc=2.10.1
GNU glibc=2.1.1
GNU glibc=2.0.3
GNU glibc=2.3.1
GNU glibc=2.3
GNU glibc=2.0
GNU glibc=2.1.1.6
GNU glibc=2.3.10
GNU glibc=2.4
GNU glibc=2.1
GNU glibc=2.3.4
GNU glibc=2.1.9
GNU glibc=2.3.3
GNU glibc=2.6.1
GNU glibc=2.0.1
GNU glibc=2.10
GNU glibc=2.5.1
GNU glibc=2.6
GNU glibc=2.0.4
GNU glibc=2.0.2
GNU glibc=2.2.1
GNU glibc=2.3.2
GNU glibc<=2.11.1
GNU glibc=2.3.6
GNU glibc=2.2.3
GNU glibc=2.5
GNU glibc=2.3.5
GNU glibc=2.8
GNU glibc=2.2.4
GNU glibc=2.1.3
GNU glibc=2.2

Event History

Jan 28, 2010
Data Sourced
via Red Hat·02:35 PM
DescriptionSeverityAffected Software
May 25, 2010
CVE Published
via Red Hat·12:00 AM
Jun 1, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:30 PM
DescriptionSeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2010-0296?

The severity of CVE-2010-0296 is classified as moderate due to its potential to cause denial of service.

2

How do I fix CVE-2010-0296?

To fix CVE-2010-0296, update the GNU C Library to version 2.11.2 or later.

3

What systems are affected by CVE-2010-0296?

CVE-2010-0296 affects various versions of the GNU C Library, specifically versions prior to 2.11.2.

4

What type of attack does CVE-2010-0296 enable?

CVE-2010-0296 enables local users to cause a denial of service through mtab corruption.

5

Can CVE-2010-0296 lead to any data modification?

Yes, CVE-2010-0296 may allow local users to modify mountpoint names under certain conditions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203