CVE-2010-0296
published 2010-06-01CVE-2010-0296: The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly…
PriorityP430high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.59%
44.8th percentile
The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.
Affected
72 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.11-1 (bookworm) | glibc 2.11-1 (bookworm) |
| debian | glibc | < glibc 2.13-8 (bookworm) | glibc 2.13-8 (bookworm) |
| gnu | glibc | <= 2.13 | — |
| gnu | glibc | <= 2.11.1 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_ubuntu7.5HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h832-96qp-642g: The addmntent function in the GNU C Library (aka glibc or libc6) 2
ghsa_unreviewed·2022-05-17·CVSS 7.2
CVE-2011-1089 [HIGH] GHSA-h832-96qp-642g: The addmntent function in the GNU C Library (aka glibc or libc6) 2
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
GHSA
GHSA-8hvc-pfj5-96x6: The encode_name macro in misc/mntent_r
ghsa_unreviewed·2022-05-02
CVE-2010-0296 [HIGH] CWE-20 GHSA-8hvc-pfj5-96x6: The encode_name macro in misc/mntent_r
The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.
OSV
CVE-2011-1089: The addmntent function in the GNU C Library (aka glibc or libc6) 2
osv·2011-04-10·CVSS 7.2
CVE-2011-1089 [HIGH] CVE-2011-1089: The addmntent function in the GNU C Library (aka glibc or libc6) 2
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
OSV
CVE-2010-0296: The encode_name macro in misc/mntent_r
osv·2010-06-01·CVSS 7.2
CVE-2010-0296 [HIGH] CVE-2010-0296: The encode_name macro in misc/mntent_r
The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.
VMware
VMware ESX third party updates for Service Console packages glibc and dhcp
vendor_vmware·2011-10-12·CVSS 4.7
CVE-2010-0296 [MEDIUM] VMware ESX third party updates for Service Console packages glibc and dhcp
VMSA-2011-0012: VMware ESX third party updates for Service Console packages glibc and dhcp
a. ESX third party update for Service Console kernel This update takes the console OS kernel package to kernel-2.6.18-238.9.1 which resolves multiple security issues. The Common Vulnerabilities and Exposures project ( cve.mitre.org) has assigned the names CVE-2010-1083, CVE-2010-2492, CVE-2010-2798, CVE-2010-2938, CVE-2010-2942, CVE-2010-2943, CVE-2010-3015, CVE-2010-3066, CVE-2010-3067, CVE-2010-3078, CVE-2010-3086, CVE-2010-3296, CVE-2010-3432, CVE-2010-3442, CVE-2010-3477, CVE-2010-3699, CVE-2010-3858, CVE-2010-3859, CVE-2010-3865, CVE-2010-3876, CVE-2010-3877, CVE-2010-3880, CVE-2010-3904, CVE-2010-4072, CVE-2010-4073, CVE-2010-4075, CVE-2010-4080, CVE-2010-4081, CVE-2010-4083, CVE-2010-4157, CV
Red Hat
glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
vendor_redhat·2011-03-03·CVSS 7.2
CVE-2011-1089 [HIGH] glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
Debian
CVE-2011-1089: glibc - The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlie...
vendor_debian·2011·CVSS 7.2
CVE-2011-1089 [HIGH] CVE-2011-1089: glibc - The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlie...
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
Scope: local
bookworm: resolved (fixed in 2.13-8)
bullseye: resolved (fixed in 2.13-8)
forky: resolved (fixed in 2.13-8)
sid: resolved (fixed in 2.13-8)
trixie: resolved (fixed in 2.13-8)
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2010-05-25·CVSS 7.5
CVE-2010-0296 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: The GNU C library did not correctly handle certain mnt entries, strfmon
arguments, and ELF program headers.
Maksymilian Arciemowicz discovered that the GNU C library did not
correctly handle integer overflows in the strfmon function. If a user
or automated system were tricked into processing a specially crafted
format string, a remote attacker could crash applications, leading to
a denial of service. (Ubuntu 10.04 was not affected.) (CVE-2008-1391)
Jeff Layton and Dan Rosenberg discovered that the GNU C library did not
correctly handle newlines in the mntent family of functions. If a local
attacker were able to inject newlines into a mount entry through other
vulnerable mount helpers, they could disrupt the system or possibly gain
root privi
Red Hat
glibc: Improper encoding of names with certain special character in utilities for writing to mtab table
vendor_redhat·2010-05-25·CVSS 7.2
CVE-2010-0296 [HIGH] glibc: Improper encoding of names with certain special character in utilities for writing to mtab table
glibc: Improper encoding of names with certain special character in utilities for writing to mtab table
The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.
Package: glibc (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-0296: glibc - The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc...
vendor_debian·2010·CVSS 7.2
CVE-2010-0296 [HIGH] CVE-2010-0296: glibc - The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc...
The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.
Scope: local
bookworm: resolved (fixed in 2.11-1)
bullseye: resolved (fixed in 2.11-1)
forky: resolved (fixed in 2.11-1)
sid: resolved (fixed in 2.11-1)
trixie: resolved (fixed in 2.11-1)
Suricata
ET WEB_SPECIFIC_APPS Script Toko Online shop_display_products.php cat_id Parameter SQL Injection
suricata·2010-07-30·CVSS 7.5
CVE-2009-0296 [HIGH] ET WEB_SPECIFIC_APPS Script Toko Online shop_display_products.php cat_id Parameter SQL Injection
ET WEB_SPECIFIC_APPS Script Toko Online shop_display_products.php cat_id Parameter SQL Injection
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Script Toko Online shop_display_products.php cat_id Parameter SQL Injection"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/shop_display_products.php?"; nocase; content:"cat_id="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; pcre:"/UNION.+SELECT/i"; reference:cve,CVE-2009-0296; reference:url,secunia.com/advisories/33661/; reference:url,milw0rm.com/exploits/7873; classtype:web-application-attack; sid:2009199; rev:6; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, signature_severity Major, tag SQL
No public exploits indexed.
Bugzilla
CVE-2011-2724 samba, cifs-utils: mount.cifs incorrect fix for CVE-2010-0547
bugzilla·2011-07-29·CVSS 7.2
CVE-2011-2724 [HIGH] CVE-2011-2724 samba, cifs-utils: mount.cifs incorrect fix for CVE-2010-0547
CVE-2011-2724 samba, cifs-utils: mount.cifs incorrect fix for CVE-2010-0547
Originally the CVE-2010-0547 identifier has been assigned by Common Vulnerabilities and Exposures to the following security issue:
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.
Later a bug was found in the upstream patch for this issue. More specifically:
check_mtab() calls check_newline() to check device and directory name. check_newline() returns EX_USAGE (1) when error is detected, while check_mtab() expects -1 to indicate an error.
This bug in original CVE-2010-0547 fix (not to propagate th
Bugzilla
CVE-2011-1089 glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
bugzilla·2011-03-18·CVSS 3.3
CVE-2011-1089 [LOW] CVE-2011-1089 glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
CVE-2011-1089 glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
Dan Rosenberg reported a flaw with suid mount helpers handle access to /etc/mtab [1], which could allow an unprivileged user to corrupt /etc/mtab and possibly manipulate mountpoint options or unmount a filesystem.
The original report follows.
This was originally sent to the now-defunct vendor-sec mailing list.
Seeing how it's a relatively low-severity issue and that we're
currently lacking a mechanism for coordination among package
maintainers and vendors, this list seems like a perfectly acceptable
venue for discussing how to fix it.
I discovered that essentially every suid mount helper that uses
addmntent() (or invokes util-linux mount, which in turn calls
addmntent()) to add entries to /etc/mtab fails to antici
Bugzilla
CVE-2010-0296 glibc: Improper encoding of names with certain special character in utilities for writing to mtab table [Fedora 11]
bugzilla·2010-06-02·CVSS 7.2
CVE-2010-0296 [HIGH] CVE-2010-0296 glibc: Improper encoding of names with certain special character in utilities for writing to mtab table [Fedora 11]
CVE-2010-0296 glibc: Improper encoding of names with certain special character in utilities for writing to mtab table [Fedora 11]
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in affected Fedora versions.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #559579:
CVE-2010-0296 glibc: Improper encoding of names with certain special character in utilities for writing to mtab table
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product. Please mention CVE ids in the RPM changelog when available.
For more information see: http://fedora
Bugzilla
CVE-2010-0547 samba: mount.cifs improper device name and mountpoint strings sanitization
bugzilla·2010-02-05·CVSS 2.1
CVE-2010-0547 [LOW] CVE-2010-0547 samba: mount.cifs improper device name and mountpoint strings sanitization
CVE-2010-0547 samba: mount.cifs improper device name and mountpoint strings sanitization
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-0547 to
the following vulnerability:
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier
does not verify that the (1) device name and (2) mountpoint strings
are composed of valid characters, which allows local users to cause a
denial of service (mtab corruption) via a crafted string.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0547
Upstream patch:
http://git.samba.org/?p=samba.git;a=commit;h=a065c177dfc8f968775593ba00dffafeebb2e054
Issue severity note:
To local, unprivileged user would be able to exploit this
flaw (to corrupt system's /etc/mtab file), the relevant
mount.cifs utility, prese
Bugzilla
CVE-2010-0296 glibc: Improper encoding of names with certain special character in utilities for writing to mtab table
bugzilla·2010-01-28·CVSS 7.2
CVE-2010-0296 [HIGH] CVE-2010-0296 glibc: Improper encoding of names with certain special character in utilities for writing to mtab table
CVE-2010-0296 glibc: Improper encoding of names with certain special character in utilities for writing to mtab table
It was found that glibc's utility, responsible for editing
of system's mtab table, improperly sanitized user supplied
mount point names containing certain special character. Local
attacker could use this flaw to add arbitrary mount points
(corrupt system's "/etc/mtab" file) or, potentially, set
unauthorized mount options. Other attacks are also possible.
Issue severity note:
The /etc/mtab file handles mounted devices and is automatically
updated by the mount command (more precisely by the dedicated
"mount" tool for relevant filesystem). Unprivileged user to
be able to run such a tool (and modify content of /etc/mtab),
this tool needs to be suid root enabled. The dedicated
http://frugalware.org/security/662http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://secunia.com/advisories/39900http://secunia.com/advisories/43830http://secunia.com/advisories/46397http://security.gentoo.org/glsa/glsa-201011-01.xmlhttp://securitytracker.com/id?1024043http://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=ab00f4eac8f4932211259ff87be83144f5211540http://www.debian.org/security/2010/dsa-2058http://www.mandriva.com/security/advisories?name=MDVSA-2010:111http://www.mandriva.com/security/advisories?name=MDVSA-2010:112http://www.redhat.com/support/errata/RHSA-2011-0412.htmlhttp://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.ubuntu.com/usn/USN-944-1http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttp://www.vupen.com/english/advisories/2010/1246http://www.vupen.com/english/advisories/2011/0863https://bugzilla.redhat.com/show_bug.cgi?id=559579https://exchange.xforce.ibmcloud.com/vulnerabilities/59240https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.htmlhttps://seclists.org/bugtraq/2019/Jun/14http://frugalware.org/security/662http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlhttp://seclists.org/fulldisclosure/2019/Jun/18http://secunia.com/advisories/39900http://secunia.com/advisories/43830http://secunia.com/advisories/46397http://security.gentoo.org/glsa/glsa-201011-01.xmlhttp://securitytracker.com/id?1024043http://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=ab00f4eac8f4932211259ff87be83144f5211540http://www.debian.org/security/2010/dsa-2058http://www.mandriva.com/security/advisories?name=MDVSA-2010:111http://www.mandriva.com/security/advisories?name=MDVSA-2010:112http://www.redhat.com/support/errata/RHSA-2011-0412.htmlhttp://www.securityfocus.com/archive/1/520102/100/0/threadedhttp://www.ubuntu.com/usn/USN-944-1http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlhttp://www.vupen.com/english/advisories/2010/1246http://www.vupen.com/english/advisories/2011/0863https://bugzilla.redhat.com/show_bug.cgi?id=559579https://exchange.xforce.ibmcloud.com/vulnerabilities/59240https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.htmlhttps://seclists.org/bugtraq/2019/Jun/14
2010-06-01
Published