Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-3286

Опубликовано: 22 сент. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.6

Описание

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

released

2.6.24-25.63
intrepid

released

2.6.27-15.43
jaunty

released

2.6.28-16.55
upstream

released

2.6.19~rc6

Показывать по

РелизСтатусПримечание
dapper

released

2.6.15-55.80
devel

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

upstream

released

2.6.19~rc6

Показывать по

EPSS

Процентиль: 27%
0.00095
Низкий

4.6 Medium

CVSS2

Связанные уязвимости

redhat
около 16 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

nvd
около 16 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

debian
около 16 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does no ...

github
больше 3 лет назад

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

oracle-oval
около 16 лет назад

ELSA-2009-1548: kernel security and bug fix update (IMPORTANT)

EPSS

Процентиль: 27%
0.00095
Низкий

4.6 Medium

CVSS2