CVE-2007-6285

NameCVE-2007-6285
DescriptionThe default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by operating a remote NFS server and creating special device files on that server, as demonstrated by the /dev/mem device.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
autofs (PTS)buster5.1.2-4fixed
bullseye5.1.7-1+deb11u2fixed
bookworm5.1.8-2+deb12u2fixed
sid5.1.9-1.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
autofssource(unstable)(not affected)
autofs5source(unstable)5.0.3-1

Notes

- autofs <not-affected> (-hosts feature not present, auto.net has nosuid,nodev)
for autofs5 see 12disable_default_auto_master.dpatch

Search for package or bug name: Reporting problems