CVE-2014-1421

NameCVE-2014-1421
Descriptionmountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mountallsource(unstable)(not affected)

Notes

- mountall <not-affected> (partman-efi in jessie uses secure umask, mount in older releases not affected)
See https://bugs.launchpad.net/ubuntu/+source/partman-efi/+bug/1390183
and http://www.ubuntu.com/usn/usn-2411-1

Search for package or bug name: Reporting problems