GNU glibc 'addmntent()' Mount Helper Local Denial of Service Vulnerability
BID:46740
Info
GNU glibc 'addmntent()' Mount Helper Local Denial of Service Vulnerability
| Bugtraq ID: | 46740 |
| Class: | Design Error |
| CVE: |
CVE-2011-1089 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 04 2011 12:00AM |
| Updated: | Nov 14 2014 12:02AM |
| Credit: | Dan Rosenberg |
| Vulnerable: |
VMWare ESXi 3.5 VMWare ESX 4.1 VMWare ESX 4.0 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop version 4 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 5 Oracle Enterprise Linux 4 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 GNU glibc2 2.3.10 GNU glibc 2.12.2 GNU glibc 2.12.1 GNU glibc 2.11.2 GNU glibc 2.11.1 GNU glibc 2.10.1 GNU glibc 2.5 GNU glibc 2.3.10 GNU glibc 2.3.4 GNU glibc 2.3.3 GNU glibc 2.3.2 GNU glibc 2.3.1 GNU glibc 2.3 GNU glibc 2.2.5 GNU glibc 2.2.4 GNU glibc 2.2.3 GNU glibc 2.2.2 GNU glibc 2.2.1 GNU glibc 2.2 GNU glibc 2.1.9 and Greater GNU glibc 2.1.9 GNU glibc 2.1.3 -10 GNU glibc 2.1.3 GNU glibc 2.1.2 GNU glibc 2.1.1 -6 GNU glibc 2.1.1 GNU glibc 2.1 GNU glibc 2.0.6 GNU glibc 2.0.5 GNU glibc 2.0.4 GNU glibc 2.0.3 GNU glibc 2.0.2 GNU glibc 2.0.1 GNU glibc 2.0 GNU glibc 2.7 GNU glibc 0 GNU Cfengine 1.2.3 Gentoo Linux Avaya Voice Portal 5.1 Avaya Proactive Contact 4.1.2 Avaya Proactive Contact 4.1.1 Avaya Proactive Contact 5.0 Avaya Proactive Contact 4.2.2 Avaya Proactive Contact 4.2.1 Avaya Proactive Contact 4.2 Avaya Proactive Contact 4.1 Avaya Proactive Contact 4.0.1 Avaya Proactive Contact 4.0 Avaya Messaging Storage Server 5.2.8 Avaya Messaging Storage Server 5.2.2 Avaya Messaging Storage Server 5.2 Avaya Message Networking 5.2.1 Avaya Message Networking 5.2.4 Avaya Message Networking 5.2.3 Avaya Message Networking 5.2.2 Avaya Message Networking 5.2 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 Avaya IQ 4.1 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IQ 4.2 Avaya IQ 4.0 Avaya IP Office Application Server 8.0 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya IP Office Application Server 6.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.1 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 4.0 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.2 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Session Manager 1.0 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 6.0 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Communication Manager 5.2 Avaya Aura Communication Manager 5.1 Avaya Aura Communication Manager 4.0 Avaya Aura Application Server 5300 SIP Core 2.1 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Avaya 96x1 IP Deskphone 6.2 Avaya 96x1 IP Deskphone 6 |
| Not Vulnerable: |
Avaya IP Office Application Server 8.1 |
Discussion
GNU glibc 'addmntent()' Mount Helper Local Denial of Service Vulnerability
GNU glibc is prone to a local denial-of-service vulnerability because suid-root mount helper applications may truncate the '/etc/mtab' file.
An attacker can exploit this issue to potentially cause filesystems to unmount.
GNU glibc is prone to a local denial-of-service vulnerability because suid-root mount helper applications may truncate the '/etc/mtab' file.
An attacker can exploit this issue to potentially cause filesystems to unmount.
Exploit / POC
GNU glibc 'addmntent()' Mount Helper Local Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
GNU glibc 'addmntent()' Mount Helper Local Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2011
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
-
Mandriva glibc-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-devel-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-doc-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-doc-pdf-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-i18ndata-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-profile-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-static-devel-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-utils-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva nscd-2.8-1.20080520.5.8mnb2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva glibc-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-devel-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-doc-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-doc-pdf-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-i18ndata-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-profile-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-static-devel-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva glibc-utils-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva nscd-2.13-6.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
References
GNU glibc 'addmntent()' Mount Helper Local Denial of Service Vulnerability
References:
References:
- glibc Homepage (GNU)
- Suid mount helpers fail to anticipate RLIMIT_FSIZE (Dan Rosenberg)
- ASA-2011-404 glibc security, bug fix, and enhancement update (RHSA-2011-1526) (Avaya)
- ASA-2012-101 Wind River Linux glibc Security Update (WIND00269484 WIND00269486 W (Avaya)
- ASA-2012-155: glibc security and bug fix update (RHSA-2012-0125) (Avaya)
- ASA-2012-156:glibc security update (RHSA-2012-0126) (Avaya)