mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain privileges by modifying this file.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-09-14 12:00
Updated : 2010-09-14 21:00
NVD link : CVE-2010-2961
Mitre link : CVE-2010-2961
JSON object : View
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Products Affected
scott_james_remnant
- mountall