CVE-2009-1072

Description

From CVE.org

nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.

Statement

This issue is not planned to be fixed in Red Hat Enterprise Linux 2.1 and 3, due to these products being in Production 3 of their maintenance life-cycles, where only qualified security errata of important or critical impact are addressed.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v2 Score Breakdown

Red HatNVDcve.org
Base Score6.24.9N/A
Attack VectorLocalLocalN/A
Access ComplexityHighLowN/A
AuthenticationNoneNoneN/A
Confidentiality ImpactCompleteNoneN/A
Integrity ImpactCompleteCompleteN/A
Availability ImpactCompleteNoneN/A

Vector

Red Hat: AV:L/AC:H/Au:N/C:C/I:C/A:C

NVD: AV:L/AC:L/Au:N/C:N/I:C/A:N

Frequently Asked Questions

Want to get errata notifications? Sign up here.