USN-985-1: mountall vulnerability
8 September 2010
Local root escalation via writable udev rules.
Releases
Packages
- mountall - filesystem mounting tool
Details
Alasdair MacGregor discovered that mountall created a udev rule file
with world-writable permissions. A local attacker could exploit this
under certain conditions to cause udev to execute arbitrary commands as
the root user.