Vulnerability Details CVE-2008-3970
pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.7%
CVSS Severity
CVSS v2 Score 6.9
Products affected by CVE-2008-3970
-
cpe:2.3:a:pam_mount:pam_mount:0.10
-
cpe:2.3:a:pam_mount:pam_mount:0.11
-
cpe:2.3:a:pam_mount:pam_mount:0.12.2
-
cpe:2.3:a:pam_mount:pam_mount:0.13
-
cpe:2.3:a:pam_mount:pam_mount:0.15
-
cpe:2.3:a:pam_mount:pam_mount:0.16
-
cpe:2.3:a:pam_mount:pam_mount:0.17
-
cpe:2.3:a:pam_mount:pam_mount:0.18
-
cpe:2.3:a:pam_mount:pam_mount:0.19
-
cpe:2.3:a:pam_mount:pam_mount:0.20
-
cpe:2.3:a:pam_mount:pam_mount:0.21
-
cpe:2.3:a:pam_mount:pam_mount:0.26
-
cpe:2.3:a:pam_mount:pam_mount:0.27
-
cpe:2.3:a:pam_mount:pam_mount:0.28
-
cpe:2.3:a:pam_mount:pam_mount:0.29
-
cpe:2.3:a:pam_mount:pam_mount:0.31
-
cpe:2.3:a:pam_mount:pam_mount:0.32
-
cpe:2.3:a:pam_mount:pam_mount:0.35
-
cpe:2.3:a:pam_mount:pam_mount:0.35.1
-
cpe:2.3:a:pam_mount:pam_mount:0.37
-
cpe:2.3:a:pam_mount:pam_mount:0.38
-
cpe:2.3:a:pam_mount:pam_mount:0.39
-
cpe:2.3:a:pam_mount:pam_mount:0.40
-
cpe:2.3:a:pam_mount:pam_mount:0.41
-
cpe:2.3:a:pam_mount:pam_mount:0.43
-
cpe:2.3:a:pam_mount:pam_mount:0.44
-
cpe:2.3:a:pam_mount:pam_mount:0.45