漏洞信息详情
Linux util-linux mount /etc/mtab文件破坏漏洞
- CNNVD编号:CNNVD-201104-074
- 危害等级: 低危
- CVE编号:
CVE-2011-1675
- 漏洞类型:
资源管理错误
- 发布时间:
2011-04-13
- 威胁类型:
本地
- 更新时间:
2011-04-13
- 厂 商:
linux - 漏洞来源:
-
漏洞简介
util-linux是一套用在Linux系统中并包含了多种系统管理工具的软件包,它提供加载、卸载、格式化、分区和管理硬盘驱动器,打开tty端口并得到内核消息等工具。
util-linux 2.19及之前版本中的mount尝试附加到/etc/mtab.tmp文件,而不是首先检查是否会影响资源的限制。本地用户可以借助带有极小RLIMIT_FSIZE值的进程,触发/etc/mtab文件的破坏。
漏洞公告
目前厂商还没有提供此漏洞的相关补丁或者升级程序,建议使用此软件的用户随时关注厂商的主页以获取最新版本:
http://www.kernel.org/
参考网址
来源: bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=688980
来源: MLIST
名称: [oss-security] 20110401 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/04/01/2
来源: MLIST
名称: [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/31/4
来源: MLIST
名称: [oss-security] 20110331 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/31/3
来源: MLIST
名称: [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/22/6
来源: MLIST
名称: [oss-security] 20110322 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/22/4
来源: MLIST
名称: [oss-security] 20110315 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/15/6
来源: MLIST
名称: [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/14/7
来源: MLIST
名称: [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/14/5
来源: MLIST
名称: [oss-security] 20110314 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/14/16
来源: MLIST
名称: [oss-security] 20110307 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/07/9
来源: MLIST
名称: [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/05/7
来源: MLIST
名称: [oss-security] 20110305 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/05/3
来源: MLIST
名称: [oss-security] 20110303 Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/04/9
来源: MLIST
名称: [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/04/12
来源: MLIST
名称: [oss-security] 20110303 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE
链接:http://openwall.com/lists/oss-security/2011/03/04/11
来源: MLIST
名称: [oss-security] 20110304 Re: Suid mount helpers fail to anticipate RLIMIT_FSIZE