Oval Definition:oval:com.redhat.rhsa:def:20070969
Revision Date:2007-11-15Version:638
Title:RHSA-2007:0969: util-linux security update (Moderate)
Description:The util-linux package contains a large variety of low-level system utilities that are necessary for a Linux system to function.

A flaw was discovered in the way that the mount and umount utilities used the setuid and setgid functions, which could lead to privileges being dropped improperly. A local user could use this flaw to run mount helper applications such as, mount.nfs, with additional privileges (CVE-2007-5191).

Users are advised to update to these erratum packages which contain a backported patch to correct this issue.
Family:unixClass:patch
Status:Reference(s):CVE-2007-5191
RHSA-2007:0969
RHSA-2007:0969-01
RHSA-2007:0969-01
Platform(s):Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • util-linux is earlier than 0:2.11y-31.24
  • AND util-linux is signed with Red Hat master key
  • losetup is earlier than 0:2.11y-31.24
  • AND losetup is signed with Red Hat master key
  • mount is earlier than 0:2.11y-31.24
  • AND mount is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND util-linux is earlier than 0:2.12a-17.el4_6.1
  • AND util-linux is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND util-linux is earlier than 0:2.13-0.45.el5_1.1
  • AND util-linux is signed with Red Hat redhatrelease key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND util-linux is earlier than 0:2.12a-17.el4_6.1
  • AND util-linux is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND util-linux is earlier than 0:2.13-0.45.el5_1.1
  • AND util-linux is signed with Red Hat redhatrelease2 key
  • BACK