S-081: autofs Security Update


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) S-081: autofs Security Update
# 1  
Old 01-02-2008
S-081: autofs Security Update

There was a security issue with the default installed configurationof autofs version 5 whereby the entry for the "hosts" map did not specify the "nosuid" mount option. The risk is MEDIUM. A local user with control of a remote nfs server could create a setuid root executable within an exported filesystem on the remote nfs server that, if mounted using the default hosts map, would allow the user to gain root privileges.


More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question