VulnerabilityModified
CVE-2010-2961
mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain privileges by modifying this file.
MEDIUM 6.9EPSS 0.47%
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain privileges by modifying this file.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.47% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- scott james remnant/mountall
- Source
- security@ubuntu.com
References
- http://secunia.com/advisories/41351Vendor Advisory
- http://www.osvdb.org/67914
- http://www.ubuntu.com/usn/USN-985-1
- http://www.vupen.com/english/advisories/2010/2342Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/mountall/+bug/591807
- http://secunia.com/advisories/41351Vendor Advisory
- http://www.osvdb.org/67914
- http://www.ubuntu.com/usn/USN-985-1
- http://www.vupen.com/english/advisories/2010/2342Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/mountall/+bug/591807
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.