The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2011-04-09 19:55
Updated : 2016-12-07 10:15
NVD link : CVE-2011-1089
Mitre link : CVE-2011-1089
JSON object : View
CWE
CWE-16
Configuration
Products Affected
gnu
- glibc