CVE Vulnerabilities

CVE-2009-2657

Published: Aug 04, 2009 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

nilfs-utils before 2.0.14 installs multiple programs with unnecessary setuid privileges, which allows local users to execute arbitrary commands via the device string in a -c command line option to mkfs.nilfs2.

Affected Software

Name Vendor Start Version End Version
Nilfs Nilf * 2.0.13 (including)
Nilfs Nilf 1.0.0 (including) 1.0.0 (including)
Nilfs Nilf 1.0.1 (including) 1.0.1 (including)
Nilfs Nilf 1.0.2 (including) 1.0.2 (including)
Nilfs Nilf 1.0.3 (including) 1.0.3 (including)
Nilfs Nilf 1.0.4 (including) 1.0.4 (including)
Nilfs Nilf 1.0.5 (including) 1.0.5 (including)
Nilfs Nilf 1.0.6 (including) 1.0.6 (including)
Nilfs Nilf 1.0.7 (including) 1.0.7 (including)
Nilfs Nilf 1.0.8 (including) 1.0.8 (including)
Nilfs Nilf 1.0.9 (including) 1.0.9 (including)
Nilfs Nilf 1.0.10 (including) 1.0.10 (including)
Nilfs Nilf 1.0.11 (including) 1.0.11 (including)
Nilfs Nilf 1.0.12 (including) 1.0.12 (including)
Nilfs Nilf 1.0.13 (including) 1.0.13 (including)
Nilfs Nilf 1.0.14 (including) 1.0.14 (including)
Nilfs Nilf 1.0.15 (including) 1.0.15 (including)
Nilfs Nilf 1.0.16 (including) 1.0.16 (including)
Nilfs Nilf 1.0.17 (including) 1.0.17 (including)
Nilfs Nilf 1.0.18 (including) 1.0.18 (including)
Nilfs Nilf 2.0.0 (including) 2.0.0 (including)
Nilfs Nilf 2.0.1 (including) 2.0.1 (including)
Nilfs Nilf 2.0.2 (including) 2.0.2 (including)
Nilfs Nilf 2.0.4 (including) 2.0.4 (including)
Nilfs Nilf 2.0.5 (including) 2.0.5 (including)
Nilfs Nilf 2.0.6 (including) 2.0.6 (including)
Nilfs Nilf 2.0.7 (including) 2.0.7 (including)
Nilfs Nilf 2.0.9 (including) 2.0.9 (including)
Nilfs Nilf 2.0.10 (including) 2.0.10 (including)
Nilfs Nilf 2.0.12 (including) 2.0.12 (including)
Nilfs2-tools Ubuntu intrepid *
Nilfs2-tools Ubuntu jaunty *
Nilfs2-tools Ubuntu karmic *

References