First published: Tue May 01 1990(Updated: )
Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun NFS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-0084 has a high severity due to its potential for privilege escalation.
To fix CVE-1999-0084, ensure that the NFS server is configured securely and restrict access rights for the mknod command.
CVE-1999-0084 affects certain NFS servers, particularly those from Sun.
The exploit method for CVE-1999-0084 involves using the mknod command to create a writable kmem device and changing the UID to 0.
Workarounds for CVE-1999-0084 include disabling mknod commands or restricting user permissions on the affected NFS servers.