[loop-aes-utils] [CVE-2007-5191] privilege escalation vulnerability

Bug #180976 reported by disabled.user
256
Affects Status Importance Assigned to Milestone
loop-aes-utils (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: loop-aes-utils

References:
DSA-1449-1 (http://www.debian.org/security/2008/dsa-1449)

Quoting:
"It was discovered that loop-aes-utils, tools for mounting and manipulating
filesystems, didn't drop privileged users and groups in the correct order
in the mount and umount commands. This could potentially allow a local
user to gain additional privileges."

CVE References

Revision history for this message
Jamie Strandboge (jdstrand) wrote :
Changed in loop-aes-utils:
status: New → Fix Released
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Sorry, marked wrong bug as Fix-Released. Re-opening.

Changed in loop-aes-utils:
status: Fix Released → New
Revision history for this message
William Grant (wgrant) wrote :

Fixed in Hardy.

Changed in loop-aes-utils:
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.