Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-1237

Опубликовано: 24 июн. 2016
Источник: redhat
CVSS3: 7.8
CVSS2: 7.2

Описание

nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.

It was found that nfsd is missing permissions check when setting ACL on files, this may allow a local users to gain access to any file by setting a crafted ACL.

Отчет

This issue does not affect any of Red Hat's shipping products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise MRG 2realtime-kernelNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1350845kernel: Missing check for permissions when setting ACL

7.8 High

CVSS3

7.2 High

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.

CVSS3: 5.5
nvd
больше 9 лет назад

nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.

CVSS3: 5.5
debian
больше 9 лет назад

nfsd in the Linux kernel through 4.6.3 allows local users to bypass in ...

CVSS3: 5.5
github
больше 3 лет назад

nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.

suse-cvrf
больше 9 лет назад

Security update for the Linux Kernel

7.8 High

CVSS3

7.2 High

CVSS2