configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash and insecure). In order to exploit the vulnerability, someone needs to mount an NFS share in order to add an executable file as root. In addition, the SUID bit must be added to this file.
Metrics
Affected Vendors & Products
References
History
Mon, 26 Aug 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-250 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-26T14:35:59.830Z
Reserved:
Link: CVE-2024-34477
Vulnrichment
Updated: 2024-08-02T02:51:11.531Z
NVD
Status : Awaiting Analysis
Published: 2024-05-27T14:15:09.470
Modified: 2024-08-26T15:35:10.043
Link: CVE-2024-34477
Redhat
No data.