Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2007-5191

Description

mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.

POC

Reference

No PoCs from references.

Github

- https://github.com/Shubhamthakur1997/CICD-Demo

- https://github.com/dcambronero/CloudGuard-ShiftLeft-CICD-AWS

- https://github.com/jaydenaung/CloudGuard-ShiftLeft-CICD-AWS