First published: Sat Dec 31 2005(Updated: )
nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SATTR privilege before setting access controls (ACL) on files on exported NFS filesystems, which allows remote attackers to bypass ACLs for readonly mounted NFS filesystems.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux kernel | =2.6.14.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3623 has a moderate severity rating due to its potential to allow remote attackers to bypass access control lists on NFS filesystems.
To fix CVE-2005-3623, update the Linux kernel to a version that addresses this vulnerability.
CVE-2005-3623 affects systems running the Linux kernel version 2.6.14.4 with NFS filesystems.
CVE-2005-3623 exploits a lack of privilege checking in setting access controls on exported NFS filesystems.
Yes, CVE-2005-3623 can be exploited remotely, allowing attackers to manipulate file permissions on vulnerable systems.