NFS: Linux CAP_MKNOD Bypass

This signature detects attempts to exploit a known vulnerability against Linux Kernel nfsd module. A successful attack can lead to security bypass.

Extended Description

The Linux Kernel is prone to an unauthorized-access vulnerability that can occur when users with certain capabilities connect to the 'nfsd' service. An attacker with authenticated access to the affected application can exploit this issue to perform privileged operations on a vulnerable computer; this may aid in further attacks.

Affected Products

Linux kernel

References

BugTraq: 34205

CVE: CVE-2009-1072

Short Name
NFS:CAP-MKNOD
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
NFS
Keywords
Bypass CAP_MKNOD CVE-2009-1072 Linux bid:34205
Release Date
10/07/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3528
False Positive
Unknown
Vendors

Red_hat

Suse

Rpath

Linux

Avaya

Ubuntu

Debian

Vmware

CVSS Score

4.9

Found a potential security threat?