Short Name |
NFS:CAP-MKNOD |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
NFS |
Keywords |
Linux CAP_MKNOD Bypass |
Release Date |
2010/10/07 |
Update Number |
1787 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against Linux Kernel nfsd module. A successful attack can lead to security bypass.
The Linux Kernel is prone to an unauthorized-access vulnerability that can occur when users with certain capabilities connect to the 'nfsd' service. An attacker with authenticated access to the affected application can exploit this issue to perform privileged operations on a vulnerable computer; this may aid in further attacks.