CVE-2014-8169

automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environment variable values instead of the values for the user used to run the mapped program, which allows local users to gain privileges via a Trojan horse program in the user home directory.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.4 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
VendorProductVersion
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_hpc_node
6.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_workstation
6.0
automount_projectautomount
5.0.8
opensuseopensuse
13.1
opensuseopensuse
13.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
autofs
bullseye
5.1.7-1+deb11u2
fixed
wheezy
not-affected
bookworm
5.1.8-2+deb12u2
fixed
sid
5.1.9-1.2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
autofs
vivid
Fixed 5.0.8-1ubuntu3
released
utopic
Fixed 5.0.8-1ubuntu1.1
released
trusty
not-affected
precise
dne
lucid
dne
autofs5
vivid
dne
utopic
dne
trusty
dne
precise
not-affected
lucid
not-affected
Common Weakness Enumeration