Permissions, Privileges, and Access Controls in Util-linux - CVE-2011-1676
Published: April 10, 2011 / Updated: August 11, 2020
Vulnerability identifier: #VU45139
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-1676
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
mount in util-linux 2.19 and earlier does not remove the /etc/mtab.tmp file after a failed attempt to add a mount entry, which allows local users to trigger corruption of the /etc/mtab file via multiple invocations.
Affected software
Util-linux
Gentoo Linux
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Juniper Cloud Native Router
Junos cRPD
Gentoo Linux
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Juniper Cloud Native Router
Junos cRPD
How to mitigate CVE-2011-1676
Install update from vendor's website.
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
External References
- http://openwall.com/lists/oss-security/2011/03/04/10
- http://openwall.com/lists/oss-security/2011/03/04/11
- http://openwall.com/lists/oss-security/2011/03/04/12
- http://openwall.com/lists/oss-security/2011/03/04/9
- http://openwall.com/lists/oss-security/2011/03/05/3
- http://openwall.com/lists/oss-security/2011/03/05/7
- http://openwall.com/lists/oss-security/2011/03/07/9
- http://openwall.com/lists/oss-security/2011/03/14/16
- http://openwall.com/lists/oss-security/2011/03/14/5
- http://openwall.com/lists/oss-security/2011/03/14/7
- http://openwall.com/lists/oss-security/2011/03/15/6
- http://openwall.com/lists/oss-security/2011/03/22/4
- http://openwall.com/lists/oss-security/2011/03/22/6
- http://openwall.com/lists/oss-security/2011/03/31/3
- http://openwall.com/lists/oss-security/2011/03/31/4
- http://openwall.com/lists/oss-security/2011/04/01/2
- https://bugzilla.redhat.com/show_bug.cgi?id=688980
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66704
Related Security Bulletins
- Multiple vulnerabilities in kernel Util-linux
- Gentoo update for util-linux
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Transformation Advisor