CVE-2007-6285

Impact:
Important
Public Date:
2007-12-20
Bugzilla:
426218: CVE-2007-6285 autofs default doesn't set nodev in /net

The MITRE CVE dictionary describes this issue as:

The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by operating a remote NFS server and creating special device files on that server, as demonstrated by the /dev/mem device.

Find out more about CVE-2007-6285 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 5 (autofs) RHSA-2007:1176 2007-12-20
Red Hat Enterprise Linux 4 (autofs5) RHSA-2007:1177 2007-12-20

Acknowledgements

Red Hat would like to thank Tim Baum for reporting this issue.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.