Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-6285
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-6285

Description:
The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by operating a remote NFS server and creating special device files on that server, as demonstrated by the /dev/mem device.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/39188

ST
  1019137

SAID
  Secunia Advisory: SA28156
  Secunia Advisory: SA28456
  Secunia Advisory: SA28168

REDHAT
  http://rhn.redhat.com/errata/RHSA-2007-1177.html
  http://rhn.redhat.com/errata/RHSA-2007-1176.html

OSVDB
  40442

MISC

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:009

FEDORA

BID
  26970


Return to the previous page.