Lucene search

K
cve[email protected]CVE-2008-3970
HistorySep 11, 2008 - 1:13 a.m.

CVE-2008-3970

2008-09-1101:13:47
CWE-264
web.nvd.nist.gov
27
pam_mount
cve-2008-3970
access restrictions
security vulnerability
nvd

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

5.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount.

Affected configurations

NVD
Node
pam_mountpam_mountMatch0.10
OR
pam_mountpam_mountMatch0.11
OR
pam_mountpam_mountMatch0.12.2
OR
pam_mountpam_mountMatch0.13
OR
pam_mountpam_mountMatch0.15
OR
pam_mountpam_mountMatch0.16
OR
pam_mountpam_mountMatch0.17
OR
pam_mountpam_mountMatch0.18
OR
pam_mountpam_mountMatch0.19
OR
pam_mountpam_mountMatch0.20
OR
pam_mountpam_mountMatch0.21
OR
pam_mountpam_mountMatch0.26
OR
pam_mountpam_mountMatch0.27
OR
pam_mountpam_mountMatch0.28
OR
pam_mountpam_mountMatch0.29
OR
pam_mountpam_mountMatch0.31
OR
pam_mountpam_mountMatch0.32
OR
pam_mountpam_mountMatch0.35
OR
pam_mountpam_mountMatch0.35.1
OR
pam_mountpam_mountMatch0.37
OR
pam_mountpam_mountMatch0.38
OR
pam_mountpam_mountMatch0.39
OR
pam_mountpam_mountMatch0.40
OR
pam_mountpam_mountMatch0.41
OR
pam_mountpam_mountMatch0.43
OR
pam_mountpam_mountMatch0.44
OR
pam_mountpam_mountMatch0.45

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

5.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%