CVE-2005-2876 describes a local privilege escalation vulnerability in the umount utility, affecting util-linux versions 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, as well as other packages like loop-aes-utils. A local user with unmount permissions can exploit the -r (remount) option to remount a filesystem with only the read-only flag, effectively clearing security-related flags such as nosuid and nodev. This vulnerability has a CVSS score of 7.2, indicating high severity with local access and low complexity leading to complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.8.1_alphaCPE matchmatch criteria | cpe:2.3:a:andries_brouwer:util-linux:2.8.1_alpha:*:*:*:*:*:*:* | ||
2.8_12CPE matchmatch criteria | cpe:2.3:a:andries_brouwer:util-linux:2.8_12:*:*:*:*:*:*:* | ||
2.9iCPE matchmatch criteria | cpe:2.3:a:andries_brouwer:util-linux:2.9i:*:*:*:*:*:*:* | ||
2.9wCPE matchmatch criteria | cpe:2.3:a:andries_brouwer:util-linux:2.9w:*:*:*:*:*:*:* | ||
2.10fCPE matchmatch criteria | cpe:2.3:a:andries_brouwer:util-linux:2.10f:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.