USN985-1 : mountall vulnerability
Synopsis :
The remote package "mountall" is missing a security patch.
Description :
Alasdair MacGregor discovered that mountall created a udev rule file
with world-writable permissions. A local attacker could exploit this
under certain conditions to cause udev to execute arbitrary commands as
the root user.
Solution :
Upgrade to :
- mountall-2.15.2 (Ubuntu 10.04)
Risk factor :
High
original thread: only registered users with at least 25 hack challenge points can see links: click here in order to visit the hack challengeshttp://www.nessus.org/plugins/index.php?view=single&id=49171