CVE-2010-2961 describes a local privilege escalation vulnerability in mountall versions prior to 2.15.2, specifically affecting Ubuntu Linux. The flaw stems from mountall.c setting insecure 0666 permissions for the root.rules file, allowing local users to modify it and gain elevated privileges. With a CVSS score of 6.9, this vulnerability has a local attack vector and medium attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an exploit (EDB-15074) is publicly available on ExploitDB, and it has received some community discussion, including a Reddit post.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.14CPE matchmatch criteria | cpe:2.3:a:scott_james_remnant:mountall:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:scott_james_remnant:mountall:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.