CVE-2011-1677
published 2011-04-10CVE-2011-1677: mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and…
PriorityP413medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.45%
36.4th percentile
mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | util-linux | < util-linux 2.20.1-1 (bookworm) | util-linux 2.20.1-1 (bookworm) |
| kernel | util-linux | >= 0 < 2.20.1-1 | 2.20.1-1 |
| kernel | util-linux | >= 0 < 2.20.1-1 | 2.20.1-1 |
| kernel | util-linux | >= 0 < 2.20.1-1 | 2.20.1-1 |
| kernel | util-linux | >= 0 < 2.20.1-1 | 2.20.1-1 |
| linux | util-linux | <= 2.19 | — |
| linux | util-linux | — | — |
| linux | util-linux | — | — |
| linux | util-linux | — | — |
| linux | util-linux | — | — |
| linux | util-linux | — | — |
| linux | util-linux | — | — |
| linux | util-linux | — | — |
| linux | util-linux | — | — |
| linux | util-linux | — | — |
| linux | util-linux | — | — |
| linux | util-linux | — | — |
| linux | util-linux | — | — |
| linux | util-linux | — | — |
| linux | util-linux | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6LOW
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
util-linux: umount may fail to remove /etc/mtab~ lock file
vendor_redhat·2011-03-03·CVSS 4.6
CVE-2011-1677 [MEDIUM] util-linux: umount may fail to remove /etc/mtab~ lock file
util-linux: umount may fail to remove /etc/mtab~ lock file
mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.
Package: util-linux (Red Hat Enterprise Linux 4) - Will not fix
Debian
CVE-2011-1677: util-linux - mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file af...
vendor_debian·2011·CVSS 4.6
CVE-2011-1677 [MEDIUM] CVE-2011-1677: util-linux - mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file af...
mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.
Scope: local
bookworm: resolved (fixed in 2.20.1-1)
bullseye: resolved (fixed in 2.20.1-1)
forky: resolved (fixed in 2.20.1-1)
sid: resolved (fixed in 2.20.1-1)
trixie: resolved (fixed in 2.20.1-1)
GHSA
GHSA-q7wr-jxh9-9p6h: mount in util-linux 2
ghsa_unreviewed·2022-05-14
CVE-2011-1677 [MEDIUM] GHSA-q7wr-jxh9-9p6h: mount in util-linux 2
mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.
OSV
CVE-2011-1677: mount in util-linux 2
osv·2011-04-10·CVSS 4.6
CVE-2011-1677 [MEDIUM] CVE-2011-1677: mount in util-linux 2
mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1675 CVE-2011-1677 util-linux-ng various flaws [fedora-all]
bugzilla·2011-04-12·CVSS 3.3
CVE-2011-1675 [LOW] CVE-2011-1675 CVE-2011-1677 util-linux-ng various flaws [fedora-all]
CVE-2011-1675 CVE-2011-1677 util-linux-ng various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=695916
Please note: this issue affects multiple suppo
Bugzilla
CVE-2011-1677 util-linux: umount may fail to remove /etc/mtab~ lock file
bugzilla·2011-04-12·CVSS 4.6
CVE-2011-1677 [MEDIUM] CVE-2011-1677 util-linux: umount may fail to remove /etc/mtab~ lock file
CVE-2011-1677 util-linux: umount may fail to remove /etc/mtab~ lock file
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1677 to
the following vulnerability:
Name: CVE-2011-1677
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1677
Assigned: 20110409
Reference: http://openwall.com/lists/oss-security/2011/03/04/11
Reference: http://openwall.com/lists/oss-security/2011/03/04/9
Reference: http://openwall.com/lists/oss-security/2011/03/04/10
Reference: http://openwall.com/lists/oss-security/2011/03/04/12
Reference: http://openwall.com/lists/oss-security/2011/03/05/3
Reference: http://openwall.com/lists/oss-security/2011/03/05/7
Reference: http://openwall.com/lists/oss-security/2011/03/07/9
Reference: http://openwall.com/lists/oss-security/2011/03/14/5
Referenc
Bugzilla
CVE-2011-1089 glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
bugzilla·2011-03-18·CVSS 3.3
CVE-2011-1089 [LOW] CVE-2011-1089 glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
CVE-2011-1089 glibc: Suid mount helpers fail to anticipate RLIMIT_FSIZE
Dan Rosenberg reported a flaw with suid mount helpers handle access to /etc/mtab [1], which could allow an unprivileged user to corrupt /etc/mtab and possibly manipulate mountpoint options or unmount a filesystem.
The original report follows.
This was originally sent to the now-defunct vendor-sec mailing list.
Seeing how it's a relatively low-severity issue and that we're
currently lacking a mechanism for coordination among package
maintainers and vendors, this list seems like a perfectly acceptable
venue for discussing how to fix it.
I discovered that essentially every suid mount helper that uses
addmntent() (or invokes util-linux mount, which in turn calls
addmntent()) to add entries to /etc/mtab fails to antici
http://openwall.com/lists/oss-security/2011/03/04/10http://openwall.com/lists/oss-security/2011/03/04/11http://openwall.com/lists/oss-security/2011/03/04/12http://openwall.com/lists/oss-security/2011/03/04/9http://openwall.com/lists/oss-security/2011/03/05/3http://openwall.com/lists/oss-security/2011/03/05/7http://openwall.com/lists/oss-security/2011/03/07/9http://openwall.com/lists/oss-security/2011/03/14/16http://openwall.com/lists/oss-security/2011/03/14/5http://openwall.com/lists/oss-security/2011/03/14/7http://openwall.com/lists/oss-security/2011/03/15/6http://openwall.com/lists/oss-security/2011/03/22/4http://openwall.com/lists/oss-security/2011/03/22/6http://openwall.com/lists/oss-security/2011/03/31/3http://openwall.com/lists/oss-security/2011/03/31/4http://openwall.com/lists/oss-security/2011/04/01/2http://secunia.com/advisories/48114http://www.redhat.com/support/errata/RHSA-2011-1691.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=688980https://exchange.xforce.ibmcloud.com/vulnerabilities/66703http://openwall.com/lists/oss-security/2011/03/04/10http://openwall.com/lists/oss-security/2011/03/04/11http://openwall.com/lists/oss-security/2011/03/04/12http://openwall.com/lists/oss-security/2011/03/04/9http://openwall.com/lists/oss-security/2011/03/05/3http://openwall.com/lists/oss-security/2011/03/05/7http://openwall.com/lists/oss-security/2011/03/07/9http://openwall.com/lists/oss-security/2011/03/14/16http://openwall.com/lists/oss-security/2011/03/14/5http://openwall.com/lists/oss-security/2011/03/14/7http://openwall.com/lists/oss-security/2011/03/15/6http://openwall.com/lists/oss-security/2011/03/22/4http://openwall.com/lists/oss-security/2011/03/22/6http://openwall.com/lists/oss-security/2011/03/31/3http://openwall.com/lists/oss-security/2011/03/31/4http://openwall.com/lists/oss-security/2011/04/01/2http://secunia.com/advisories/48114http://www.redhat.com/support/errata/RHSA-2011-1691.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=688980https://exchange.xforce.ibmcloud.com/vulnerabilities/66703
2011-04-10
Published