---
title: "CVE-2014-1421\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-1421?format=md
keywords: index, follow
---

# CVE-2014-1421

Publication date 18 November 2014

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask
when using the mount utility, which allows local users to bypass intended
access restrictions via unspecified vectors.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2014-1421?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| mountall | 14.10 utopic | Fixed 2.54ubuntu0.14.10.1 |
| 14.04 LTS trusty | Not affected |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

This is only an issue when combined with the mount utility in
utopic and newer.

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1421)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-1421)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-1421)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-1421)

### Related Ubuntu Security Notices (USN)

+ [USN-2411-1](https://usn.ubuntu.com/USN-2411-1)
+ mountall vulnerability
+ 18 November 2014

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2014-1421>
