Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-3286

Опубликовано: 09 сент. 2009
Источник: redhat
CVSS2: 4.6

Описание

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

Отчет

This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, and Red Hat Enterprise MRG.

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=524520kernel: O_EXCL creates on NFSv4 are broken

4.6 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 16 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

nvd
больше 16 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

debian
больше 16 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does no ...

github
почти 4 года назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

oracle-oval
больше 16 лет назад

ELSA-2009-1548: kernel security and bug fix update (IMPORTANT)

4.6 Medium

CVSS2