missing input validation in pmount: arbitrary mount as non-root

Posted by Imre RAD on Jul 15

Summary:
——–
pmount is a wrapper around the standard mount program which permits
normal users to mount removable devices without a matching /etc/fstab
entry.
Due to a missing input validation check local users could mount devices
to arbitrary destinations and thus taking over the targeted system
completely.

Prerequisites:
————–
Local user access to the target
Pmount 0.9.23 or older to be installed (any version at time of writing…