CVE-2007-5191
published 2007-10-04CVE-2007-5191: mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow…
PriorityP427high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.44%
35.7th percentile
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | util-linux | < util-linux 2.13-8 (bookworm) | util-linux 2.13-8 (bookworm) |
| fedoraproject | fedora | — | — |
| kernel | util-linux | <= 2.13.1.1 | — |
| kernel | util-linux | >= 0 < 2.13-8 | 2.13-8 |
| kernel | util-linux | >= 0 < 2.13-8 | 2.13-8 |
| kernel | util-linux | >= 0 < 2.13-8 | 2.13-8 |
| kernel | util-linux | >= 0 < 2.13-8 | 2.13-8 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x6mx-7fcg-2j6w: mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which mi
ghsa_unreviewed·2022-05-01
CVE-2007-5191 [HIGH] CWE-252 GHSA-x6mx-7fcg-2j6w: mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which mi
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
OSV
CVE-2007-5191: mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which mi
osv·2007-10-04·CVSS 7.2
CVE-2007-5191 [HIGH] CVE-2007-5191: mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which mi
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
VMware
Updated service console patches.
vendor_vmware·2008-01-07·CVSS 1.2
CVE-2007-3108 [LOW] Updated service console patches.
VMSA-2008-0001: Updated service console patches.
Updated service console patches. VMware Security Advisory VMware Security Advisory Advisory ID: VMware Security Advisory Synopsis: Updated service console patches. VMware Security Advisory Issue date: VMware Security Advisory Updated on:
CVEs: CVE-2007-3108, CVE-2007-4572, CVE-2007-5116, CVE-2007-5135, CVE-2007-5191, CVE-2007-5360, CVE-2007-5398
Ubuntu
util-linux vulnerability
vendor_ubuntu·2007-10-22
CVE-2007-5191 util-linux vulnerability
Title: util-linux vulnerability
Summary: util-linux vulnerability
Ludwig Nussel discovered that mount and umount did not properly
drop privileges when using helper programs. Local attackers may be
able to bypass security restrictions and gain root privileges using
programs such as mount.nfs or mount.cifs.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
util-linux (u)mount doesn't drop privileges properly when calling helpers
vendor_redhat·2007-09-20·CVSS 7.2
CVE-2007-5191 [HIGH] util-linux (u)mount doesn't drop privileges properly when calling helpers
util-linux (u)mount doesn't drop privileges properly when calling helpers
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
Debian
CVE-2007-5191: util-linux - mount and umount in util-linux and loop-aes-utils call the setuid and setgid fun...
vendor_debian·2007·CVSS 7.2
CVE-2007-5191 [HIGH] CVE-2007-5191: util-linux - mount and umount in util-linux and loop-aes-utils call the setuid and setgid fun...
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
Scope: local
bookworm: resolved (fixed in 2.13-8)
bullseye: resolved (fixed in 2.13-8)
forky: resolved (fixed in 2.13-8)
sid: resolved (fixed in 2.13-8)
trixie: resolved (fixed in 2.13-8)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-5191 util-linux (u)mount doesn't drop privileges properly when calling helpers [F7]
bugzilla·2007-10-05·CVSS 7.2
CVE-2007-5191 [HIGH] CVE-2007-5191 util-linux (u)mount doesn't drop privileges properly when calling helpers [F7]
CVE-2007-5191 util-linux (u)mount doesn't drop privileges properly when calling helpers [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Fixed. Update to util-linux-2.13-0.54.1.fc7.
Bugzilla
CVE-2007-5191 util-linux (u)mount doesn't drop privileges properly when calling helpers [FC6]
bugzilla·2007-10-05·CVSS 7.2
CVE-2007-5191 [HIGH] CVE-2007-5191 util-linux (u)mount doesn't drop privileges properly when calling helpers [FC6]
CVE-2007-5191 util-linux (u)mount doesn't drop privileges properly when calling helpers [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
Fixed in 0.49.fc6, FEDORA-2007-722 http://lwn.net/Alerts/254681/
Bugzilla
CVE-2007-5191 util-linux (u)mount doesn't drop privileges properly when calling helpers
bugzilla·2007-10-05·CVSS 7.2
CVE-2007-5191 [HIGH] CVE-2007-5191 util-linux (u)mount doesn't drop privileges properly when calling helpers
CVE-2007-5191 util-linux (u)mount doesn't drop privileges properly when calling helpers
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-5191 to the following vulnerability:
mount and umount in util-linux call the setuid and setgid functions in the
wrong order and do not check the return values, which might allow attackers to
gain privileges via helpers such as mount.nfs.
References:
http://git.kernel.org/?p=utils/util-linux-ng/util-linux-ng.git;a=commit;h=ebbeb2c7ac1b00b6083905957837a271e80b187e
Discussion:
util-linux-2.13-0.54.1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2007-0969.html
F
http://bugs.gentoo.org/show_bug.cgi?id=195390http://frontal2.mandriva.com/en/security/advisories?name=MDKSA-2007:198http://git.kernel.org/?p=utils/util-linux-ng/util-linux-ng.git%3Ba=commit%3Bh=ebbeb2c7ac1b00b6083905957837a271e80b187ehttp://lists.opensuse.org/opensuse-security-announce/2007-10/msg00008.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000002.htmlhttp://secunia.com/advisories/27104http://secunia.com/advisories/27122http://secunia.com/advisories/27145http://secunia.com/advisories/27188http://secunia.com/advisories/27283http://secunia.com/advisories/27354http://secunia.com/advisories/27399http://secunia.com/advisories/27687http://secunia.com/advisories/28348http://secunia.com/advisories/28349http://secunia.com/advisories/28368http://secunia.com/advisories/28469http://security.gentoo.org/glsa/glsa-200710-18.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2008-023.htmhttp://www.debian.org/security/2008/dsa-1449http://www.debian.org/security/2008/dsa-1450http://www.redhat.com/support/errata/RHSA-2007-0969.htmlhttp://www.securityfocus.com/archive/1/485936/100/0/threadedhttp://www.securityfocus.com/archive/1/486859/100/0/threadedhttp://www.securityfocus.com/bid/25973http://www.securitytracker.com/id?1018782http://www.ubuntu.com/usn/usn-533-1http://www.vmware.com/security/advisories/VMSA-2008-0001.htmlhttp://www.vupen.com/english/advisories/2007/3417http://www.vupen.com/english/advisories/2008/0064https://bugzilla.redhat.com/show_bug.cgi?id=320041https://issues.rpath.com/browse/RPL-1757https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10101https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00144.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=195390http://frontal2.mandriva.com/en/security/advisories?name=MDKSA-2007:198http://git.kernel.org/?p=utils/util-linux-ng/util-linux-ng.git%3Ba=commit%3Bh=ebbeb2c7ac1b00b6083905957837a271e80b187ehttp://lists.opensuse.org/opensuse-security-announce/2007-10/msg00008.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000002.htmlhttp://secunia.com/advisories/27104http://secunia.com/advisories/27122http://secunia.com/advisories/27145http://secunia.com/advisories/27188http://secunia.com/advisories/27283http://secunia.com/advisories/27354http://secunia.com/advisories/27399http://secunia.com/advisories/27687http://secunia.com/advisories/28348http://secunia.com/advisories/28349http://secunia.com/advisories/28368http://secunia.com/advisories/28469http://security.gentoo.org/glsa/glsa-200710-18.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2008-023.htmhttp://www.debian.org/security/2008/dsa-1449http://www.debian.org/security/2008/dsa-1450http://www.redhat.com/support/errata/RHSA-2007-0969.htmlhttp://www.securityfocus.com/archive/1/485936/100/0/threadedhttp://www.securityfocus.com/archive/1/486859/100/0/threadedhttp://www.securityfocus.com/bid/25973http://www.securitytracker.com/id?1018782http://www.ubuntu.com/usn/usn-533-1http://www.vmware.com/security/advisories/VMSA-2008-0001.htmlhttp://www.vupen.com/english/advisories/2007/3417http://www.vupen.com/english/advisories/2008/0064https://bugzilla.redhat.com/show_bug.cgi?id=320041https://issues.rpath.com/browse/RPL-1757https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10101https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00144.html
2007-10-04
Published