Bug 19563 (CVE-2010-0296) - Missing escaping of backslashes in addmntent (CVE-2010-0296)
Summary: Missing escaping of backslashes in addmntent (CVE-2010-0296)
Status: RESOLVED FIXED
Alias: CVE-2010-0296
Product: glibc
Classification: Unclassified
Component: libc (show other bugs)
Version: 2.24
: P2 normal
Target Milestone: 2.12
Assignee: Not yet assigned to anyone
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-02-04 06:59 UTC by Florian Weimer
Modified: 2016-02-04 07:00 UTC (History)
1 user (show)

See Also:
Host:
Target:
Build:
Last reconfirmed:
fweimer: security+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Florian Weimer 2016-02-04 06:59:02 UTC
The encode_name macro, used by addmntent, did not escape backslashes, allowing unprivileged users to create crafted /etc/mtab entries on some systems.
Comment 1 Florian Weimer 2016-02-04 07:00:09 UTC
Fixed in:

https://sourceware.org/git/?p=glibc.git;a=commit;h=ab00f4eac8f4932211259ff87be83144f5211540

for glibc 2.12.