autofs nodev Mount Option Privilege Escalation Vulnerability

The 'autofs' utility is prone to a privilege-escalation vulnerability because of a flaw in its default configuration. Filesystems mounted under '/net' using the 'hosts' automount map do not have the 'nodev' mount option enabled by default.

Attackers can leverage this issue to interact with arbitrary system devices. Successful exploits will completely compromise affected computers.


 

Privacy Statement
Copyright 2010, SecurityFocus