Upstream information

CVE-2011-1678 at MITRE

Description

smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.

SUSE information

Overall state of this security issue: Resolved

This issue is currently not rated by SUSE as it is not affecting the SUSE Enterprise products.

CVSS v2 Scores
CVSS detail National Vulnerability Database
Base Score 3.3
Vector AV:L/AC:M/Au:N/C:P/I:P/A:N
Access Vector Local
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None
SUSE Bugzilla entry: 686552 [VERIFIED / FIXED]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Server 11 SP2
  • cifs-utils >= 5.1-0.4.9
Patchnames:
SUSE Linux Enterprise Server 11 SP2 GA cifs-utils-5.1-0.4.9
SUSE Linux Enterprise Server 11 SP3
  • cifs-utils >= 5.1-0.11.1
Patchnames:
SUSE Linux Enterprise Server 11 SP3 GA cifs-utils-5.1-0.11.1
SUSE Linux Enterprise Server 11 SP4
  • cifs-utils >= 5.1-0.14.46
Patchnames:
SUSE Linux Enterprise Server 11 SP4 GA cifs-utils-5.1-0.14.46


SUSE Timeline for this CVE

CVE page created: Fri Jun 28 12:20:10 2013
CVE page last modified: Mon Oct 6 18:17:10 2025