CVE-2012-1586

NameCVE-2012-1586
Descriptionmount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error message.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs665923

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cifs-utils (PTS)jessie, jessie (lts)2:6.4-1+deb8u1fixed
stretch (security), stretch (lts), stretch2:6.7-1+deb9u1fixed
buster (security), buster, buster (lts)2:6.8-2+deb10u1fixed
bullseye2:6.11-3.1+deb11u2fixed
bullseye (security)2:6.11-3.1+deb11u1fixed
bookworm2:7.0-2fixed
sid, trixie2:7.0-2.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cifs-utilssource(unstable)2:5.3-2unimportant665923

Notes

Harmless information leak, if a user can perform arbitrary CIFS mounts they probably
can do a lot more with this

Search for package or bug name: Reporting problems