Back to list
*Note: Email address will appear as "user domain ext" to prevent harvesting.
missing input validation in pmount: arbitrary mount as non-root
Jul 13 2016 10:00AM
Imre RAD (imre rad search-lab hu)
pmount is a wrapper around the standard mount program which permits
normal users to mount removable devices without a matching /etc/fstab entry.
Due to a missing input validation check local users could mount devices
to arbitrary destinations and thus taking over the targeted syste...
[ more ]
Copyright 2010, SecurityFocus