Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-3286
HistorySep 22, 2009 - 12:00 a.m.

CVE-2009-3286

2009-09-2200:00:00
ubuntu.com
ubuntu.com
17

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

10.1%

NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not
properly clean up an inode when an O_EXCL create fails, which causes files
to be created with insecure settings such as setuid bits, and possibly
allows local users to gain privileges, related to the execution of the
do_open_permission function even when a create fails.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchlinux< 2.6.24-25.63UNKNOWN
ubuntu8.10noarchlinux< 2.6.27-15.43UNKNOWN
ubuntu9.04noarchlinux< 2.6.28-16.55UNKNOWN
ubuntu6.06noarchlinux-source-2.6.15< 2.6.15-55.80UNKNOWN

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

10.1%