Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-3286

Опубликовано: 09 сент. 2009
Источник: redhat
CVSS2: 4.6
EPSS Низкий

Описание

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

Отчет

This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 3, 4, and Red Hat Enterprise MRG.

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=524520kernel: O_EXCL creates on NFSv4 are broken

EPSS

Процентиль: 28%
0.00095
Низкий

4.6 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 16 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

nvd
почти 16 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

debian
почти 16 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does no ...

github
около 3 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

oracle-oval
больше 15 лет назад

ELSA-2009-1548: kernel security and bug fix update (IMPORTANT)

EPSS

Процентиль: 28%
0.00095
Низкий

4.6 Medium

CVSS2