Hi all,
1.5 and 1.6 are both security releases, which fix long-standing issues with 9mount that allow local privilege escalation. If you have 9mount installed on any machines which users other than yourself have access to, it is recommended to upgrade ASAP.
Summary of changes:
- "nodev" and "nosuid" mount options are now actually effective, and are always enforced for non-root users
- improved robustness of file permission checks to prevent race conditions (eg. an attacker pointing 9mount at an empty directory they have write access to, but replacing it with a symlink to an unwritable area after 9mount completes its permission checks)
Cheers,
-sqweek