CVE-2007-5964
EPSS 0.48%
Description
The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/net filesystem) map, which allows local users to gain privileges via a setuid program on a remote NFS server.
How to fix CVE-2007-5964
To remediate CVE-2007-5964, upgrade the affected package to a fixed version below.
- Debian/autofs—upgrade to 3.1.4-8 or later
Is CVE-2007-5964 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.1.4-8