CVE-2013-0157
published 2014-01-21CVE-2013-0157: (a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.38%
29.9th percentile
(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line option or (2) attempting to mount a non-existent device, which generates different error messages depending on whether the directory exists.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | util-linux | < util-linux 2.20.1-5.5 (bookworm) | util-linux 2.20.1-5.5 (bookworm) |
| kernel | util-linux | — | — |
| kernel | util-linux | — | — |
| kernel | util-linux | >= 0 < 2.20.1-5.5 | 2.20.1-5.5 |
| kernel | util-linux | >= 0 < 2.20.1-5.5 | 2.20.1-5.5 |
| kernel | util-linux | >= 0 < 2.20.1-5.5 | 2.20.1-5.5 |
| kernel | util-linux | >= 0 < 2.20.1-5.5 | 2.20.1-5.5 |
| openstack | horizon | >= 2013.2 < 2013.2.4 | 2013.2.4 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_redhat4.3MEDIUM
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template
vendor_redhat·2014-04-08·CVSS 4.3
CVE-2014-0157 [MEDIUM] CWE-79 openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template
openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template
Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.
Package: python-django-horizon (Red Hat OpenStack Platform 3) - Will not fix
Red Hat
util-linux: mount folder existence information disclosure
vendor_redhat·2013-01-05·CVSS 2.1
CVE-2013-0157 [LOW] util-linux: mount folder existence information disclosure
util-linux: mount folder existence information disclosure
(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line option or (2) attempting to mount a non-existent device, which generates different error messages depending on whether the directory exists.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Package: util-linux (Red Hat Enterprise
Debian
CVE-2013-0157: util-linux - (a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versio...
vendor_debian·2013·CVSS 2.1
CVE-2013-0157 [LOW] CVE-2013-0157: util-linux - (a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versio...
(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line option or (2) attempting to mount a non-existent device, which generates different error messages depending on whether the directory exists.
Scope: local
bookworm: resolved (fixed in 2.20.1-5.5)
bullseye: resolved (fixed in 2.20.1-5.5)
forky: resolved (fixed in 2.20.1-5.5)
sid: resolved (fixed in 2.20.1-5.5)
trixie: resolved (fixed in 2.20.1-5.5)
GHSA
OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting
ghsa·2022-05-14
CVE-2014-0157 [MEDIUM] CWE-79 OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting
OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting
Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.
GHSA
GHSA-5f9c-xx25-xwrv: (a) mount and (b) umount in util-linux 2
ghsa_unreviewed·2022-05-05
CVE-2013-0157 [LOW] CWE-200 GHSA-5f9c-xx25-xwrv: (a) mount and (b) umount in util-linux 2
(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line option or (2) attempting to mount a non-existent device, which generates different error messages depending on whether the directory exists.
OSV
CVE-2013-0157: (a) mount and (b) umount in util-linux 2
osv·2014-01-21·CVSS 2.1
CVE-2013-0157 [LOW] CVE-2013-0157: (a) mount and (b) umount in util-linux 2
(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line option or (2) attempting to mount a non-existent device, which generates different error messages depending on whether the directory exists.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0157 openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template
bugzilla·2014-04-01·CVSS 4.3
CVE-2014-0157 [MEDIUM] CVE-2014-0157 openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template
CVE-2014-0157 openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template
It was reported that, if an Horizon user were tricked into using a malicious template in the Orchestration/Stack section of Horizon, it would be possible for an attacker to conduct cross-site scripting (XSS) attacks.
The original report notes "2013.2.1 version up to 2013.2.2" are affected.
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Cristian Fiorentino from Intel as the original reporter.
Discussion:
This issue is public now:
http://seclists.org/oss-sec/2014/q2/35
---
Created python-django-horizon tracking bugs for this issue:
Affects: fedora-all [bug 1085825]
Affects: epel-6 [bug 1085826]
---
python-djan
Bugzilla
CVE-2013-0157 util-linux: mount folder existence information disclosure [fedora-16]
bugzilla·2013-01-07·CVSS 2.1
CVE-2013-0157 [LOW] CVE-2013-0157 util-linux: mount folder existence information disclosure [fedora-16]
CVE-2013-0157 util-linux: mount folder existence information disclosure [fedora-16]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-16 tracking bu
Bugzilla
CVE-2013-0157 util-linux: mount folder existence information disclosure [fedora-17]
bugzilla·2013-01-07·CVSS 2.1
CVE-2013-0157 [LOW] CVE-2013-0157 util-linux: mount folder existence information disclosure [fedora-17]
CVE-2013-0157 util-linux: mount folder existence information disclosure [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-17 tracking bu
Bugzilla
CVE-2013-0157 util-linux: mount folder existence information disclosure
bugzilla·2013-01-06·CVSS 2.1
CVE-2013-0157 [LOW] CVE-2013-0157 util-linux: mount folder existence information disclosure
CVE-2013-0157 util-linux: mount folder existence information disclosure
This was originally reported by Jann Horn ([email protected]):
mount discloses information about folders not accessible for a user:
$ ls -ld /root/.ssh
ls: cannot access /root/.ssh: Permission denied
$ ls -ld /root/.foo
ls: cannot access /root/.foo: Permission denied
First variant:
$ mount --guess-fstype /root/.ssh/../../dev/sda1
ext4
$ mount --guess-fstype /root/.foo/../../dev/sda1
unknown
Second one:
$ mount /root/.ssh/../../dev/cdrom
mount: no medium found on /dev/sr0
$ mount /root/.foo/../../dev/cdrom
mount: can't find /root/.foo/../../dev/cdrom in /etc/fstab or /etc/mtab
These issues were, as far as I can see, fixed in the following upstream commits:
- 0377ef91270d06592a0d4dd009c29e7b1ff9c9b8
- 33c5f
http://bugs.debian.org/697464http://marc.info/?l=oss-security&m=135749410312247&w=2http://osvdb.org/88953http://rhn.redhat.com/errata/RHSA-2013-0517.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:154https://bugzilla.redhat.com/show_bug.cgi?id=892330http://bugs.debian.org/697464http://marc.info/?l=oss-security&m=135749410312247&w=2http://osvdb.org/88953http://rhn.redhat.com/errata/RHSA-2013-0517.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:154https://bugzilla.redhat.com/show_bug.cgi?id=892330
2014-01-21
Published