CVE-2007-5964
published 2007-12-13CVE-2007-5964: The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/net…
PriorityP422medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.48%
38.2th percentile
The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/net filesystem) map, which allows local users to gain privileges via a setuid program on a remote NFS server.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | autofs | < autofs 3.1.4-8 (bookworm) | autofs 3.1.4-8 (bookworm) |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
autofs defaults don't restrict suid in /net
vendor_redhat·2007-12-12·CVSS 6.9
CVE-2007-5964 [MEDIUM] autofs defaults don't restrict suid in /net
autofs defaults don't restrict suid in /net
The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/net filesystem) map, which allows local users to gain privileges via a setuid program on a remote NFS server.
Debian
CVE-2007-5964: autofs - The default configuration of autofs 5 in some Linux distributions, such as Red H...
vendor_debian·2007·CVSS 6.9
CVE-2007-5964 [MEDIUM] CVE-2007-5964: autofs - The default configuration of autofs 5 in some Linux distributions, such as Red H...
The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/net filesystem) map, which allows local users to gain privileges via a setuid program on a remote NFS server.
Scope: local
bookworm: resolved (fixed in 3.1.4-8)
bullseye: resolved (fixed in 3.1.4-8)
forky: resolved (fixed in 3.1.4-8)
sid: resolved (fixed in 3.1.4-8)
trixie: resolved (fixed in 3.1.4-8)
GHSA
GHSA-fvq8-m245-r4cr: The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/
ghsa_unreviewed·2022-05-01
CVE-2007-5964 [MEDIUM] GHSA-fvq8-m245-r4cr: The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/
The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/net filesystem) map, which allows local users to gain privileges via a setuid program on a remote NFS server.
OSV
CVE-2007-5964: The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/
osv·2007-12-13·CVSS 6.9
CVE-2007-5964 [MEDIUM] CVE-2007-5964: The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/
The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/net filesystem) map, which allows local users to gain privileges via a setuid program on a remote NFS server.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-5964 Privilege Escalation (from local system) through /net autofs mount configuration bug
bugzilla·2007-12-04·CVSS 6.9
CVE-2007-5964 [MEDIUM] CVE-2007-5964 Privilege Escalation (from local system) through /net autofs mount configuration bug
CVE-2007-5964 Privilege Escalation (from local system) through /net autofs mount configuration bug
Description of problem:
A stock install of RHEL5 and Fedora 8 (and possibly earlier versions) have /net
managed by autofs (look at /etc/auto.master).
Unfortunately, the "nosuid" mount option is not specified, meaning that any
system auto-mounted under /net may have arbitrary suid root binaries.
Version-Release number of selected component (if applicable): RHEL 5, Fedora 8,
possibly others
How reproducible: Always
Steps to Reproduce:
1. set up an NFS server with an suid root binary in an exported directory.
2. log into a system running fedora 8/rhel5. Ensure autofs is running.
3. as a non-root user on the fedora8/rhel5 box, change directory to
/net/hostname_of_nfs_server.tld/exported_pat
Bugzilla
CVE-2007-5964 autofs defaults don't restrict suid in /net
bugzilla·2007-12-04·CVSS 6.9
CVE-2007-5964 [MEDIUM] CVE-2007-5964 autofs defaults don't restrict suid in /net
CVE-2007-5964 autofs defaults don't restrict suid in /net
Reported to the Red Hat Security Response Team via [email protected]:
"A stock install of RHEL5 and Fedora 8 (and possibly earlier versions) have
/net managed by autofs (look at /etc/auto.master).
Unfortunately, the "nosuid" mount option is not specified, meaning that any
system auto-mounted under /net may have arbitrary suid root binaries.
How to exploit this vulnerability:
An attacker can set up an NFS server on a remote host, and connect to the
vulnerable system with an unprivileged user account.
>From here, the attacker can change directory to /net/remote.host.tld/export
on the vulnerable system, and execute arbitrary "setuid root"
binaries that they have placed on their nfs server."
Acknowledgements:
Red Hat would like
http://osvdb.org/40441http://secunia.com/advisories/28052http://secunia.com/advisories/28097http://secunia.com/advisories/28456http://securitytracker.com/id?1019087http://www.mandriva.com/security/advisories?name=MDVSA-2008:009http://www.redhat.com/support/errata/RHSA-2007-1128.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1129.htmlhttp://www.securityfocus.com/bid/26841https://bugzilla.redhat.com/show_bug.cgi?id=409701https://bugzilla.redhat.com/show_bug.cgi?id=410031https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10158https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00474.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00549.htmlhttp://osvdb.org/40441http://secunia.com/advisories/28052http://secunia.com/advisories/28097http://secunia.com/advisories/28456http://securitytracker.com/id?1019087http://www.mandriva.com/security/advisories?name=MDVSA-2008:009http://www.redhat.com/support/errata/RHSA-2007-1128.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1129.htmlhttp://www.securityfocus.com/bid/26841https://bugzilla.redhat.com/show_bug.cgi?id=409701https://bugzilla.redhat.com/show_bug.cgi?id=410031https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10158https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00474.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00549.html
2007-12-13
Published