CVE-2011-1089
published 2011-04-10CVE-2011-1089: The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab…
PriorityP47low3.3CVSS 2.0
AVLACMAuNCPIPAN
EPSS
0.42%
34.2th percentile
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
Affected
118 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cifs-utils | < cifs-utils 2:5.1-1 (bookworm) | cifs-utils 2:5.1-1 (bookworm) |
| debian | glibc | < glibc 2.13-8 (bookworm) | glibc 2.13-8 (bookworm) |
| debian | nfs-utils | < nfs-utils 1:1.2.3-3 (bookworm) | nfs-utils 1:1.2.3-3 (bookworm) |
| debian | open-vm-tools | < open-vm-tools 2:8.4.2+2011.08.21-471295-1 (bookworm) | open-vm-tools 2:8.4.2+2011.08.21-471295-1 (bookworm) |
| debian | samba | < cifs-utils 2:5.1-1 (bookworm) | cifs-utils 2:5.1-1 (bookworm) |
| debian | util-linux | < util-linux 2.20.1-1 (bookworm) | util-linux 2.20.1-1 (bookworm) |
| gnu | glibc | <= 2.13 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c72p-cwvx-7724: The nfs_addmntent function in support/nfs/nfs_mntent
ghsa_unreviewed·2022-05-17·CVSS 3.3
CVE-2011-1749 [LOW] CWE-20 GHSA-c72p-cwvx-7724: The nfs_addmntent function in support/nfs/nfs_mntent
The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
GHSA
GHSA-h832-96qp-642g: The addmntent function in the GNU C Library (aka glibc or libc6) 2
ghsa_unreviewed·2022-05-17·CVSS 7.2
CVE-2011-1089 [HIGH] GHSA-h832-96qp-642g: The addmntent function in the GNU C Library (aka glibc or libc6) 2
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
GHSA
GHSA-rv69-mh9p-xcg6: ncpfs 2
ghsa_unreviewed·2022-05-17·CVSS 3.3
CVE-2011-1679 [LOW] CWE-20 GHSA-rv69-mh9p-xcg6: ncpfs 2
ncpfs 2.2.6 and earlier attempts to use (1) ncpmount to append to the /etc/mtab file and (2) ncpumount to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
GHSA
GHSA-v7g7-rpcw-4f58: smbfs in Samba 3
ghsa_unreviewed·2022-05-17·CVSS 3.3
CVE-2011-1678 [LOW] CWE-20 GHSA-v7g7-rpcw-4f58: smbfs in Samba 3
smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
GHSA
GHSA-94c3-vwq8-frg9: vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8
ghsa_unreviewed·2022-05-17·CVSS 3.3
CVE-2011-1681 [LOW] GHSA-94c3-vwq8-frg9: vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8
vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8.4.2-261024 and earlier attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to trigger corruption of this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
GHSA
GHSA-rjp4-x6wp-r79j: mount in util-linux 2
ghsa_unreviewed·2022-05-14·CVSS 3.3
CVE-2011-1675 [LOW] GHSA-rjp4-x6wp-r79j: mount in util-linux 2
mount in util-linux 2.19 and earlier attempts to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
OSV
CVE-2011-1749: The nfs_addmntent function in support/nfs/nfs_mntent
osv·2014-02-26·CVSS 3.3
CVE-2011-1749 [LOW] CVE-2011-1749: The nfs_addmntent function in support/nfs/nfs_mntent
The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
OSV
CVE-2011-1675: mount in util-linux 2
osv·2011-04-10·CVSS 3.3
CVE-2011-1675 [LOW] CVE-2011-1675: mount in util-linux 2
mount in util-linux 2.19 and earlier attempts to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
OSV
CVE-2011-1681: vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8
osv·2011-04-10·CVSS 3.3
CVE-2011-1681 [LOW] CVE-2011-1681: vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8
vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8.4.2-261024 and earlier attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to trigger corruption of this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
OSV
CVE-2011-1089: The addmntent function in the GNU C Library (aka glibc or libc6) 2
osv·2011-04-10·CVSS 7.2
CVE-2011-1089 [HIGH] CVE-2011-1089: The addmntent function in the GNU C Library (aka glibc or libc6) 2
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
OSV
CVE-2011-1678: smbfs in Samba 3
osv·2011-04-10·CVSS 3.3
CVE-2011-1678 [LOW] CVE-2011-1678: smbfs in Samba 3
smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
VMware
VMware security updates for vCSA, vCenter Server, and ESXi
vendor_vmware·2012-12-20·CVSS 4.0
CVE-2009-5029 [MEDIUM] VMware security updates for vCSA, vCenter Server, and ESXi
VMSA-2012-0018: VMware security updates for vCSA, vCenter Server, and ESXi
a. vCenter Server Appliance directory traversal The vCenter Server Appliance (vCSA) contains a directory traversal vulnerability that allows an authenticated remote user to retrieve arbitrary files. Exploitation of this issue may expose sensitive information stored on the server. VMware would like to thank Alexander Minozhenko from ERPScan for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-6324 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Replace with/ Apply Patch VMware Product vCSA Product Vers
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2012-03-09·CVSS 6.8
CVE-2009-5029 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Multiple vulnerabilities were discovered and fixed in the GNU C Library.
It was discovered that the GNU C Library did not properly handle
integer overflows in the timezone handling code. An attacker could use
this to possibly execute arbitrary code by convincing an application
to load a maliciously constructed tzfile. (CVE-2009-5029)
It was discovered that the GNU C Library did not properly handle
passwd.adjunct.byname map entries in the Network Information Service
(NIS) code in the name service caching daemon (nscd). An attacker
could use this to obtain the encrypted passwords of NIS accounts.
This issue only affected Ubuntu 8.04 LTS. (CVE-2010-0015)
Chris Evans reported that the GNU C Library did not properly
calculate the amount of memor
Red Hat
nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE
vendor_redhat·2011-04-19·CVSS 3.3
CVE-2011-1749 [LOW] nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE
nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE
The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
Statement: This issue did not affect the versions of nfs-utils as shipped with Red Hat Enterprise Linux 4 as it did not include include mount.nfs. It was addressed in Red Hat Enterprise Linux 5 and 6 via RHSA-2012:0310 and RHSA-2011:1534 respectively.
Package: nfs-utils (Red Hat Enterprise Linux 4) - Not affected
Red Hat
util-linux: mount fails to anticipate RLIMIT_FSIZE
vendor_redhat·2011-03-03·CVSS 3.3
CVE-2011-1675 [LOW] util-linux: mount fails to anticipate RLIMIT_FSIZE
util-linux: mount fails to anticipate RLIMIT_FSIZE
mount in util-linux 2.19 and earlier attempts to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
Package: util-linux (Red Hat Enterprise Linux 4) - Will not fix
Red Hat
glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
vendor_redhat·2011-03-03·CVSS 7.2
CVE-2011-1089 [HIGH] glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
Red Hat
samba/cifs-utils: mount.cifs and umount.cifs fail to anticipate RLIMIT_FSIZE
vendor_redhat·2011-03-03·CVSS 3.3
CVE-2011-1678 [LOW] samba/cifs-utils: mount.cifs and umount.cifs fail to anticipate RLIMIT_FSIZE
samba/cifs-utils: mount.cifs and umount.cifs fail to anticipate RLIMIT_FSIZE
smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
Statement: On Red Hat Enterprise Linux, by default, mount.cifs is not provided with the setuid bit enabled. If a user has turned on the setuid bit (via chmod +s /sbin/mount.cifs), they would be affected by this issue, and can work around the problem by removing the setuid bit.
Red Hat Enterprise Linux 3 does not provide the mount.cifs program.
Debian
CVE-2011-1749: nfs-utils - The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in ...
vendor_debian·2011·CVSS 3.3
CVE-2011-1749 [LOW] CVE-2011-1749: nfs-utils - The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in ...
The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
Scope: local
bookworm: resolved (fixed in 1:1.2.3-3)
bullseye: resolved (fixed in 1:1.2.3-3)
forky: resolved (fixed in 1:1.2.3-3)
sid: resolved (fixed in 1:1.2.3-3)
trixie: resolved (fixed in 1:1.2.3-3)
Debian
CVE-2011-1678: cifs-utils - smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the...
vendor_debian·2011·CVSS 3.3
CVE-2011-1678 [LOW] CVE-2011-1678: cifs-utils - smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the...
smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
Scope: local
bookworm: resolved (fixed in 2:5.1-1)
bullseye: resolved (fixed in 2:5.1-1)
forky: resolved (fixed in 2:5.1-1)
sid: resolved (fixed in 2:5.1-1)
trixie: resolved (fixed in 2:5.1-1)
Debian
CVE-2011-1681: open-vm-tools - vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8.4....
vendor_debian·2011·CVSS 3.3
CVE-2011-1681 [LOW] CVE-2011-1681: open-vm-tools - vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8.4....
vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8.4.2-261024 and earlier attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to trigger corruption of this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
Scope: local
bookworm: resolved (fixed in 2:8.4.2+2011.08.21-471295-1)
bullseye: resolved (fixed in 2:8.4.2+2011.08.21-471295-1)
forky: resolved (fixed in 2:8.4.2+2011.08.21-471295-1)
sid: resolved (fixed in 2:8.4.2+2011.08.21-471295-1)
trixie: resolved (fixed in 2:8.4.2+2011.08.21-471295-1)
Debian
CVE-2011-1675: util-linux - mount in util-linux 2.19 and earlier attempts to append to the /etc/mtab.tmp fil...
vendor_debian·2011·CVSS 3.3
CVE-2011-1675 [LOW] CVE-2011-1675: util-linux - mount in util-linux 2.19 and earlier attempts to append to the /etc/mtab.tmp fil...
mount in util-linux 2.19 and earlier attempts to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
Scope: local
bookworm: resolved (fixed in 2.20.1-1)
bullseye: resolved (fixed in 2.20.1-1)
forky: resolved (fixed in 2.20.1-1)
sid: resolved (fixed in 2.20.1-1)
trixie: resolved (fixed in 2.20.1-1)
Debian
CVE-2011-1089: glibc - The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlie...
vendor_debian·2011·CVSS 7.2
CVE-2011-1089 [HIGH] CVE-2011-1089: glibc - The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlie...
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
Scope: local
bookworm: resolved (fixed in 2.13-8)
bullseye: resolved (fixed in 2.13-8)
forky: resolved (fixed in 2.13-8)
sid: resolved (fixed in 2.13-8)
trixie: resolved (fixed in 2.13-8)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1749 nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE
bugzilla·2011-04-19·CVSS 3.3
CVE-2011-1749 [LOW] CVE-2011-1749 nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE
CVE-2011-1749 nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE
It was found that mount.nfs suffers from the same flaw as other mount helpers (see CVE-2011-1089). Instead of using addmntent(), nfs-utils implements its own similar function (nfs_addmntent()) which also fails to anticipate whether resource limits would interfere with correctly writing to /etc/mtab. A local user could use this to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value.
In nfs-utils-1.2.3/support/nfs/nfs_mntent.c:
126 int
127 nfs_addmntent (mntFILE *mfp, struct mntent *mnt) {
128 char *m1, *m2, *m3, *m4;
129 int res;
130
131 if (fseek (mfp->mntent_fp, 0, SEEK_END))
132 return 1; /* failure */
133
134 m1 = mangle(mnt->mnt_fsname);
135 m2 = mangle(mnt->mnt_dir);
136 m3 = mang
Bugzilla
CVE-2011-1675 util-linux: mount fails to anticipate RLIMIT_FSIZE
bugzilla·2011-04-12·CVSS 3.3
CVE-2011-1675 [LOW] CVE-2011-1675 util-linux: mount fails to anticipate RLIMIT_FSIZE
CVE-2011-1675 util-linux: mount fails to anticipate RLIMIT_FSIZE
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1675 to
the following vulnerability:
Name: CVE-2011-1675
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1675
Assigned: 20110409
Reference: http://openwall.com/lists/oss-security/2011/03/04/9
mount in util-linux 2.19 and earlier attempts to append to the
/etc/mtab.tmp file without first checking whether resource limits
would interfere, which allows local users to trigger corruption of the
/etc/mtab file via a process with a small RLIMIT_FSIZE value, a
related issue to CVE-2011-1089.
Discussion:
Created util-linux-ng tracking bugs for this issue
Affects: fedora-all [bug 695940]
---
Summary of the patches that were committed upstream to add
Bugzilla
CVE-2011-1678 samba/cifs-utils: mount.cifs and umount.cifs fail to anticipate RLIMIT_FSIZE
bugzilla·2011-04-12·CVSS 3.3
CVE-2011-1678 [LOW] CVE-2011-1678 samba/cifs-utils: mount.cifs and umount.cifs fail to anticipate RLIMIT_FSIZE
CVE-2011-1678 samba/cifs-utils: mount.cifs and umount.cifs fail to anticipate RLIMIT_FSIZE
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1678 tothe following vulnerability:
Name: CVE-2011-1678
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1678
Assigned: 20110409
Reference: http://openwall.com/lists/oss-security/2011/03/04/9
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=688980
smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to
append to the /etc/mtab file and (2) umount.cifs to append to the
/etc/mtab.tmp file without first checking whether resource limits
would interfere, which allows local users to trigger corruption of the
/etc/mtab file via a process with a small RLIMIT_FSIZE value, a
related issue to CVE-2011-1089.
Disc
Bugzilla
CVE-2011-1679 ncpfs: ncpmount and ncpumount fail to anticipate RLIMIT_FSIZE
bugzilla·2011-04-12·CVSS 3.3
CVE-2011-1679 [LOW] CVE-2011-1679 ncpfs: ncpmount and ncpumount fail to anticipate RLIMIT_FSIZE
CVE-2011-1679 ncpfs: ncpmount and ncpumount fail to anticipate RLIMIT_FSIZE
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1679 to
the following vulnerability:
Name: CVE-2011-1679
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1679
Assigned: 20110409
Reference: http://openwall.com/lists/oss-security/2011/03/04/9
Reference: https://bugzilla.redhat.com/show_bug.cgi?id=688980
ncpfs 2.2.6 and earlier attempts to use (1) ncpmount to append to the
/etc/mtab file and (2) ncpumount to append to the /etc/mtab.tmp file
without first checking whether resource limits would interfere, which
allows local users to trigger corruption of the /etc/mtab file via a
process with a small RLIMIT_FSIZE value, a related issue to
CVE-2011-1089.
Discussion:
Created ncpfs track
Bugzilla
CVE-2011-1675 CVE-2011-1677 util-linux-ng various flaws [fedora-all]
bugzilla·2011-04-12·CVSS 3.3
CVE-2011-1675 [LOW] CVE-2011-1675 CVE-2011-1677 util-linux-ng various flaws [fedora-all]
CVE-2011-1675 CVE-2011-1677 util-linux-ng various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=695916
Please note: this issue affects multiple suppo
Bugzilla
CVE-2011-1089 glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
bugzilla·2011-03-18·CVSS 3.3
CVE-2011-1089 [LOW] CVE-2011-1089 glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
CVE-2011-1089 glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
Dan Rosenberg reported a flaw with suid mount helpers handle access to /etc/mtab [1], which could allow an unprivileged user to corrupt /etc/mtab and possibly manipulate mountpoint options or unmount a filesystem.
The original report follows.
This was originally sent to the now-defunct vendor-sec mailing list.
Seeing how it's a relatively low-severity issue and that we're
currently lacking a mechanism for coordination among package
maintainers and vendors, this list seems like a perfectly acceptable
venue for discussing how to fix it.
I discovered that essentially every suid mount helper that uses
addmntent() (or invokes util-linux mount, which in turn calls
addmntent()) to add entries to /etc/mtab fails to antici
http://openwall.com/lists/oss-security/2011/03/04/10http://openwall.com/lists/oss-security/2011/03/04/11http://openwall.com/lists/oss-security/2011/03/04/12http://openwall.com/lists/oss-security/2011/03/04/9http://openwall.com/lists/oss-security/2011/03/05/3http://openwall.com/lists/oss-security/2011/03/05/7http://openwall.com/lists/oss-security/2011/03/07/9http://openwall.com/lists/oss-security/2011/03/14/16http://openwall.com/lists/oss-security/2011/03/14/5http://openwall.com/lists/oss-security/2011/03/14/7http://openwall.com/lists/oss-security/2011/03/15/6http://openwall.com/lists/oss-security/2011/03/22/4http://openwall.com/lists/oss-security/2011/03/22/6http://openwall.com/lists/oss-security/2011/03/31/3http://openwall.com/lists/oss-security/2011/03/31/4http://openwall.com/lists/oss-security/2011/04/01/2http://sourceware.org/bugzilla/show_bug.cgi?id=12625http://www.mandriva.com/security/advisories?name=MDVSA-2011:178http://www.mandriva.com/security/advisories?name=MDVSA-2011:179http://www.redhat.com/support/errata/RHSA-2011-1526.htmlhttp://www.securityfocus.com/bid/46740https://bugzilla.redhat.com/show_bug.cgi?id=688980http://openwall.com/lists/oss-security/2011/03/04/10http://openwall.com/lists/oss-security/2011/03/04/11http://openwall.com/lists/oss-security/2011/03/04/12http://openwall.com/lists/oss-security/2011/03/04/9http://openwall.com/lists/oss-security/2011/03/05/3http://openwall.com/lists/oss-security/2011/03/05/7http://openwall.com/lists/oss-security/2011/03/07/9http://openwall.com/lists/oss-security/2011/03/14/16http://openwall.com/lists/oss-security/2011/03/14/5http://openwall.com/lists/oss-security/2011/03/14/7http://openwall.com/lists/oss-security/2011/03/15/6http://openwall.com/lists/oss-security/2011/03/22/4http://openwall.com/lists/oss-security/2011/03/22/6http://openwall.com/lists/oss-security/2011/03/31/3http://openwall.com/lists/oss-security/2011/03/31/4http://openwall.com/lists/oss-security/2011/04/01/2http://sourceware.org/bugzilla/show_bug.cgi?id=12625http://www.mandriva.com/security/advisories?name=MDVSA-2011:178http://www.mandriva.com/security/advisories?name=MDVSA-2011:179http://www.redhat.com/support/errata/RHSA-2011-1526.htmlhttp://www.securityfocus.com/bid/46740https://bugzilla.redhat.com/show_bug.cgi?id=688980
2011-04-10
Published