6.9
CVSSv2

CVE-2008-3970

Published: 11/09/2008 Updated: 07/11/2023
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

pam_mount 0.10 up to and including 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount.

Vulnerable Product Search on Vulmon Subscribe to Product

pam mount pam mount 0.11

pam mount pam mount 0.45

pam mount pam mount 0.32

pam mount pam mount 0.15

pam mount pam mount 0.28

pam mount pam mount 0.39

pam mount pam mount 0.17

pam mount pam mount 0.35

pam mount pam mount 0.10

pam mount pam mount 0.41

pam mount pam mount 0.29

pam mount pam mount 0.40

pam mount pam mount 0.37

pam mount pam mount 0.38

pam mount pam mount 0.31

pam mount pam mount 0.12.2

pam mount pam mount 0.43

pam mount pam mount 0.16

pam mount pam mount 0.20

pam mount pam mount 0.19

pam mount pam mount 0.35.1

pam mount pam mount 0.13

pam mount pam mount 0.44

pam mount pam mount 0.18

pam mount pam mount 0.26

pam mount pam mount 0.27

pam mount pam mount 0.21

Vendor Advisories

Debian Bug report logs - #499841 CVE-2008-3970: does not verify mountpoint and source ownership before mounting a user-defined volume Package: libpam-mount; Maintainer for libpam-mount is Jochen Sprickerhof <jspricke@debianorg>; Source for libpam-mount is src:libpam-mount (PTS, buildd, popcon) Reported by: Stefan Fritsch &l ...