vendor:
fdmount
by:
WaR and Zav
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: fdmount
Affected Version From: S.u.S.E. 4.0 and later, Mandrake Linux 7.0, TurboLinux 6.0 and earlier
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2002
Buffer Overflow in fdmount Program
A buffer overflow exists in the 0.8 version of the fdmount program, distributed with a number of popular versions of Linux. By supplying a large, well crafted buffer containing machine executable code in place of the mount point, it is possible for users in the 'floppy' group to execute arbitrary commands as root.
Mitigation:
Upgrade to the latest version of fdmount program