CVE-2005-2876
published 2005-09-13CVE-2005-2876: umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages such as loop-aes-utils, allows local users with unmount permissions to gain…
PriorityP423high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.43%
34.7th percentile
umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages such as loop-aes-utils, allows local users with unmount permissions to gain privileges via the -r (remount) option, which causes the file system to be remounted with just the read-only flag, which effectively clears the nosuid, nodev, and other flags.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
| andries_brouwer | util-linux | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2MEDIUM
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
umount vulnerability
vendor_ubuntu·2005-09-19
CVE-2005-2876 umount vulnerability
Title: umount vulnerability
Summary: umount vulnerability
David Watson discovered that "umount -r" removed some restrictive
mount options like the "nosuid" flag. If /etc/fstab contains
user-mountable removable devices which specify the "nosuid" flag
(which is common practice for such devices), a local attacker could
exploit this to execute arbitrary programs with root privileges by
calling "umount -r" on a removable device.
This does not affect the default Ubuntu configuration. Since Ubuntu
mounts removable devices automatically, there is normally no need to
configure them manually in /etc/fstab.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-09-13·CVSS 7.2
CVE-2005-2876 [HIGH] security flaw
security flaw
umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages such as loop-aes-utils, allows local users with unmount permissions to gain privileges via the -r (remount) option, which causes the file system to be remounted with just the read-only flag, which effectively clears the nosuid, nodev, and other flags.
Debian
CVE-2005-2876: util-linux - umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages ...
vendor_debian·2005·CVSS 7.2
CVE-2005-2876 [HIGH] CVE-2005-2876: util-linux - umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages ...
umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages such as loop-aes-utils, allows local users with unmount permissions to gain privileges via the -r (remount) option, which causes the file system to be remounted with just the read-only flag, which effectively clears the nosuid, nodev, and other flags.
Scope: local
bookworm: resolved (fixed in 2.12p-8)
bullseye: resolved (fixed in 2.12p-8)
forky: resolved (fixed in 2.12p-8)
sid: resolved (fixed in 2.12p-8)
trixie: resolved (fixed in 2.12p-8)
GHSA
GHSA-96fj-vjjr-c856: umount in util-linux 2
ghsa_unreviewed·2022-05-01
CVE-2005-2876 [HIGH] GHSA-96fj-vjjr-c856: umount in util-linux 2
umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages such as loop-aes-utils, allows local users with unmount permissions to gain privileges via the -r (remount) option, which causes the file system to be remounted with just the read-only flag, which effectively clears the nosuid, nodev, and other flags.
OSV
CVE-2005-2876: umount in util-linux 2
osv·2005-09-13·CVSS 7.2
CVE-2005-2876 [HIGH] CVE-2005-2876: umount in util-linux 2
umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages such as loop-aes-utils, allows local users with unmount permissions to gain privileges via the -r (remount) option, which causes the file system to be remounted with just the read-only flag, which effectively clears the nosuid, nodev, and other flags.
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=112656096125857&w=2http://marc.info/?l=bugtraq&m=112690609622266&w=2http://secunia.com/advisories/16785http://secunia.com/advisories/16988http://secunia.com/advisories/17004http://secunia.com/advisories/17027http://secunia.com/advisories/17133http://secunia.com/advisories/17154http://secunia.com/advisories/18502http://sunsolve.sun.com/search/document.do?assetkey=1-26-101960-1http://support.avaya.com/elmodocs2/security/ASA-2006-014.htmhttp://www.debian.org/security/2005/dsa-823http://www.debian.org/security/2005/dsa-825http://www.novell.com/linux/security/advisories/2005_21_sr.htmlhttp://www.osvdb.org/19369http://www.securityfocus.com/archive/1/419774/100/0/threadedhttp://www.securityfocus.com/bid/14816http://www.ubuntu.com/usn/usn-184-1https://exchange.xforce.ibmcloud.com/vulnerabilities/22241https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10921http://marc.info/?l=bugtraq&m=112656096125857&w=2http://marc.info/?l=bugtraq&m=112690609622266&w=2http://secunia.com/advisories/16785http://secunia.com/advisories/16988http://secunia.com/advisories/17004http://secunia.com/advisories/17027http://secunia.com/advisories/17133http://secunia.com/advisories/17154http://secunia.com/advisories/18502http://sunsolve.sun.com/search/document.do?assetkey=1-26-101960-1http://support.avaya.com/elmodocs2/security/ASA-2006-014.htmhttp://www.debian.org/security/2005/dsa-823http://www.debian.org/security/2005/dsa-825http://www.novell.com/linux/security/advisories/2005_21_sr.htmlhttp://www.osvdb.org/19369http://www.securityfocus.com/archive/1/419774/100/0/threadedhttp://www.securityfocus.com/bid/14816http://www.ubuntu.com/usn/usn-184-1https://exchange.xforce.ibmcloud.com/vulnerabilities/22241https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10921
2005-09-13
Published