CVE
- Id
- 169
- CVE No.
- CVE-1999-0169
- Status
- Candidate
- Description
- NFS allows attackers to read and write any file on the system by specifying a false UID.
- Phase
- Proposed (19990714)
- Votes
- ACCEPT(2) Frech, Northcutt | MODIFY(1) Baker | REJECT(1) Shostack
- Comments
- Shostack> this is not a vulnerability but a design feature. | Baker> Maybe we should reword it so that it is clear that this was a problem to something like: | | "A remote attacker could read/write files to the system with root-level permissions on NFS servers that fail to properly check the UID."