4.9

CVE-2009-1072

nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version < 2.6.28.9
OpensuseOpensuse Version10.3
OpensuseOpensuse Version11.0
OpensuseOpensuse Version11.1
SuseLinux Enterprise Desktop Version10 Updatesp2
SuseLinux Enterprise Server Version10 Updatesp2
DebianDebian Linux Version4.0
DebianDebian Linux Version5.0
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version8.04
CanonicalUbuntu Linux Version8.10
CanonicalUbuntu Linux Version9.04
VMwareVcenter Server Version4.0 Update-
   MicrosoftWindows Version-
VMwareVirtualcenter Version2.0.2
   MicrosoftWindows Version-
VMwareVirtualcenter Version2.5
   MicrosoftWindows Version-
VMwareServer Version2.0.0
VMwareEsx Version3.0.3
VMwareEsx Version3.5
VMwareEsx Version4.0
VMwareVma Version4.0
   RedhatEnterprise Linux Version5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.8% 0.718
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:C/A:N
http://www.securityfocus.com/bid/34205
Third Party Advisory
VDB Entry