util-linux: mount folder existence information disclosure
Published Jan 21, 2014
2.1
LOWCVSS 2.0
EPSS 0.38%
Description
(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line option or (2) attempting to mount a non-existent device, which generates different error messages depending on whether the directory exists.
Affected products
No data.
- 2.14.1
- 2.17.2
No data.
Red Hat Enterprise Linux 6
util-linux-ng-0:2.17.2-12.9.el6
Fixed · RHSA-2013:0517
Red Hat Enterprise Linux 4
util-linux
Will not fix
Red Hat Enterprise Linux 5
util-linux
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | util-linux-ng-0:2.17.2-12.9.el6 | Fixed | RHSA-2013:0517 |
| Red Hat Enterprise Linux 4 | util-linux | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | util-linux | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
References (10)
- http://bugs.debian.org/697464 x_refsource_CONFIRM
- http://marc.info/?l=oss-security&m=135749410312247&w=2 mailing-listx_refsource_MLIST
- http://osvdb.org/88953 vdb-entryx_refsource_OSVDB
- http://rhn.redhat.com/errata/RHSA-2013-0517.html vendor-advisoryx_refsource_REDHAT
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:154 vendor-advisoryx_refsource_MANDRIVA
- https://access.redhat.com/security/cve/CVE-2013-0157 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=892330 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0198 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-0157
- https://www.cve.org/CVERecord?id=CVE-2013-0157
| Link | Providers | Tags |
|---|---|---|
| http://bugs.debian.org/697464 | x_refsource_CONFIRM | |
| http://marc.info/?l=oss-security&m=135749410312247&w=2 | mailing-listx_refsource_MLIST | |
| http://osvdb.org/88953 | vdb-entryx_refsource_OSVDB | |
| http://rhn.redhat.com/errata/RHSA-2013-0517.html | vendor-advisoryx_refsource_REDHAT | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2013:154 | vendor-advisoryx_refsource_MANDRIVA | |
| https://access.redhat.com/security/cve/CVE-2013-0157 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=892330 | x_refsource_CONFIRMIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0198 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-0157 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-0157 |
Change history (0)
No recorded changes yet.