Bug#384922: nfs-kernel-server: root_squash is broken

2006-08-27 Thread Paul Szabo
Please see also http://lists.grok.org.uk/pipermail/full-disclosure/2006-August/049079.html Paul Szabo [EMAIL PROTECTED] http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject o

Bug#384922: nfs-kernel-server: root_squash is broken

2006-08-27 Thread Paul Szabo
Package: nfs-kernel-server Version: 1:1.0.6-3.1 Severity: critical Justification: root security hole NFS uses root_squash by default, in part (mainly?) so as to make it more difficult to create a setuid-root file in a writable export: protect the exporting server from a compromise of the mounting