CVE-2008-3970

pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount.
Configurations

Configuration 1

cpe:2.3:a:pam_mount:pam_mount:0.11:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.45:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.32:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.15:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.28:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.39:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.17:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.35:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.10:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.41:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.29:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.40:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.37:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.38:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.31:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.12.2:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.43:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.16:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.20:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.19:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.35.1:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.13:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.44:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.18:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.26:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.27:*:*:*:*:*:*:*
cpe:2.3:a:pam_mount:pam_mount:0.21:*:*:*:*:*:*:*

Information

Published : 2008-09-11 01:13

Updated : 2017-08-08 01:32


NVD link : CVE-2008-3970

Mitre link : CVE-2008-3970

Products Affected
No products.
CWE