CVE-2011-1089Glibc vulnerability

CWE-1615 documents8 sources
Severity
3.3LOWNVD
CNA7.2OSV7.2
EPSS
0.1%
top 74.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 10
Latest updateMay 17

Description

The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.

CVSS vector

AV:L/AC:M/C:P/I:P/A:NExploitability: 3.4 | Impact: 4.9

Affected Packages2 packages

Debiangnu/glibc< 2.13-8+3
NVDgnu/glibc2.13+57

🔴Vulnerability Details

3
GHSA
GHSA-h832-96qp-642g: The addmntent function in the GNU C Library (aka glibc or libc6) 22022-05-17
OSV
CVE-2011-1089: The addmntent function in the GNU C Library (aka glibc or libc6) 22011-04-10
CVEList
CVE-2011-1089: The addmntent function in the GNU C Library (aka glibc or libc6) 22011-04-10

📋Vendor Advisories

6
Ubuntu
GNU C Library vulnerabilities2012-03-09
Red Hat
nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE2011-04-19
Red Hat
glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE2011-03-03
Red Hat
util-linux: mount fails to anticipate RLIMIT_FSIZE2011-03-03
Red Hat
samba/cifs-utils: mount.cifs and umount.cifs fail to anticipate RLIMIT_FSIZE2011-03-03

💬Community

4
Bugzilla
CVE-2011-1749 nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE2011-04-19
Bugzilla
CVE-2011-1675 util-linux: mount fails to anticipate RLIMIT_FSIZE2011-04-12
Bugzilla
CVE-2011-1679 ncpfs: ncpmount and ncpumount fail to anticipate RLIMIT_FSIZE2011-04-12
Bugzilla
CVE-2011-1089 glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE2011-03-18
CVE-2011-1089 — GNU Glibc vulnerability | cvebase