Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-3286

Опубликовано: 22 сент. 2009
Источник: ubuntu
Приоритет: medium
CVSS2: 4.6

Описание

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

released

2.6.24-25.63
intrepid

released

2.6.27-15.43
jaunty

released

2.6.28-16.55
upstream

released

2.6.19~rc6

Показывать по

РелизСтатусПримечание
dapper

released

2.6.15-55.80
devel

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

upstream

released

2.6.19~rc6

Показывать по

4.6 Medium

CVSS2

Связанные уязвимости

redhat
почти 16 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

nvd
почти 16 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

debian
почти 16 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does no ...

github
около 3 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

oracle-oval
больше 15 лет назад

ELSA-2009-1548: kernel security and bug fix update (IMPORTANT)

4.6 Medium

CVSS2