CVE-2010-4661: Malicious File Upload
Sebastian Krahmer reported that the udisks service (via D-BUS) could be used to load arbitrary Linux kernel modules. Since "mount -t $NAME" is called, this also triggers a "modprobe -q -- $NAME" which will load the Linux kernel module from /lib/modules/.
The upstream bug report is: https://bugs.freedesktop.org/showbug.cgi?id=32232 and no upstream fix has been made as of yet, although the upstream bug report has a few suggestions on how to correct this.
Other sources
udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4661?
The severity of CVE-2010-4661 is high.
How does CVE-2010-4661 affect udisks?
CVE-2010-4661 allows a local user to load arbitrary Linux kernel modules using udisks before version 1.0.3.
Which software versions are affected by CVE-2010-4661?
Versions up to and excluding udisks 1.0.3, Redhat Enterprise Linux 6.0, Debian Linux 8.0, Opensuse 11.4, Fedoraproject Fedora, and Opensuse 11.3 are affected.
How can I fix CVE-2010-4661?
Upgrade udisks to version 1.0.3 or apply the appropriate security patches provided by the software vendor.
Where can I find more information about CVE-2010-4661?
You can find more information about CVE-2010-4661 at the following references: http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00000.html, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4661, https://access.redhat.com/security/cve/cve-2010-4661.