[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-1630Date: (C)2009-05-14   (M)2024-02-22


The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.4
Exploit Score: 3.4
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://www.securityfocus.com/archive/1/505254/100/0/threaded
http://www.securityfocus.com/archive/1/507985/100/0/threaded
BID-34934
SECUNIA-35106
SECUNIA-35298
SECUNIA-35394
SECUNIA-35656
SECUNIA-35847
SECUNIA-36051
SECUNIA-36327
SECUNIA-37471
ADV-2009-1331
ADV-2009-3316
DSA-1809
DSA-1844
DSA-1865
MDVSA-2009:135
MDVSA-2009:148
RHSA-2009:1157
SUSE-SA:2009:031
SUSE-SA:2009:038
USN-793-1
http://article.gmane.org/gmane.linux.nfs/26592
http://linux-nfs.org/pipermail/nfsv4/2006-November/005313.html
http://linux-nfs.org/pipermail/nfsv4/2006-November/005323.html
http://www.openwall.com/lists/oss-security/2009/05/13/2
http://bugzilla.linux-nfs.org/show_bug.cgi?id=131
http://wiki.rpath.com/Advisories:rPSA-2009-0111
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
https://bugzilla.redhat.com/show_bug.cgi?id=500297
oval:org.mitre.oval:def:8543
oval:org.mitre.oval:def:9990

CPE    11
cpe:/o:opensuse:opensuse:11.1
cpe:/o:opensuse:opensuse:11.0
cpe:/o:debian:debian_linux:4.0
cpe:/o:debian:debian_linux:5.0
...
CWE    1
CWE-264
OVAL    16
oval:org.secpod.oval:def:202070
oval:org.secpod.oval:def:500599
oval:org.secpod.oval:def:202123
oval:org.secpod.oval:def:400080
...

© SecPod Technologies