Bug 426218 (CVE-2007-6285)

Summary: CVE-2007-6285 autofs default doesn't set nodev in /net
Product: [Other] Security Response Reporter: Josh Bressers <bressers>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: ikent, jmoyer, kreilly, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-01-09 09:40:46 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 426219, 426220, 426221, 426222, 426399, 426400, 426401    
Bug Blocks:    

Description Josh Bressers 2007-12-19 12:50:25 UTC
It was reported to secalert that the autofs defaults do not set the
nodev NFS option.

bug 410031 notes the missing nosuid option by default for the /net autofs
filesystems, the fix for that issue did not take into account that there was
also a missing nodev option for these filesystems.

Without the nodev option, it is possible for an attacker to mount a remote
filesystem which could give them access to various devices that should normally
have restricted access, such as /dev/mem, and various hardware devices.


Red Hat would like to thank Tim Baum for reporting this issue.

Comment 8 Tomas Hoger 2007-12-20 19:19:59 UTC
Lifting embargo.

Comment 9 Tomas Hoger 2007-12-20 19:54:15 UTC
Fixed now in affected version of Red Hat Enterprise Linux:


Comment 10 Tomas Hoger 2008-01-09 09:40:46 UTC
Updates now available also in stable Fedora repositories: