Red Hat Bugzilla – Bug 320041
CVE-2007-5191 util-linux (u)mount doesn't drop privileges properly when calling helpers
Last modified: 2008-01-14 10:01:36 EST
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-5191 to the following vulnerability:
mount and umount in util-linux call the setuid and setgid functions in the
wrong order and do not check the return values, which might allow attackers to
gain privileges via helpers such as mount.nfs.
util-linux-2.13-0.54.1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
This issue was addressed in:
Red Hat Enterprise Linux: