Vulnerability Description
The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 2.6.29.3 |
| Opensuse | Opensuse | 11.0 |
| Debian | Debian Linux | 4.0 |
| Canonical | Ubuntu Linux | 6.06 |
| Vmware | Esx | 2.5.5 |
Related Weaknesses (CWE)
References
- http://article.gmane.org/gmane.linux.nfs/26592Exploit
- http://bugzilla.linux-nfs.org/show_bug.cgi?id=131Issue TrackingPatchThird Party Advisory
- http://linux-nfs.org/pipermail/nfsv4/2006-November/005313.htmlBroken Link
- http://linux-nfs.org/pipermail/nfsv4/2006-November/005323.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.htmlMailing ListThird Party Advisory
- http://secunia.com/advisories/35106Broken Link
- http://secunia.com/advisories/35298Broken Link
- http://secunia.com/advisories/35394Broken Link
- http://secunia.com/advisories/35656Broken Link
- http://secunia.com/advisories/35847Broken Link
- http://secunia.com/advisories/36051Broken Link
- http://secunia.com/advisories/36327Broken Link
- http://secunia.com/advisories/37471Broken Link
- http://wiki.rpath.com/Advisories:rPSA-2009-0111Broken Link
FAQ
What is CVE-2009-1630?
CVE-2009-1630 is a vulnerability with a CVSS score of 4.4 (MEDIUM). The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) perm...
How severe is CVE-2009-1630?
CVE-2009-1630 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-1630?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Opensuse Opensuse, Debian Debian Linux, Canonical Ubuntu Linux, Vmware Esx.