Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line option or (2) attempting to mount a non-existent device, which generates different error messages depending on whether the directory exists.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
util-linux Package ‘mount’和‘umount’信息泄露漏洞
Vulnerability Description
util-linux是一套用在Linux系统中并包含了多种系统管理工具的软件包,它提供加载、卸载、格式化、分区和管理硬盘驱动器,打开tty端口并得到内核消息等工具。 util-linux 2.14.1和2.17.2版本中的mount和umount中存在信息泄露漏洞。本地攻击者可利用该漏洞通过使用--guess-fstype命令行选项或尝试安装不存在的设备,利用该漏洞通过系统产生的不同错误信息来判断目录是否存在。
CVSS Information
N/A
Vulnerability Type
N/A