COMMAND
nfsd
SYSTEMS AFFECTED
Most NFS running unpatched w/ 16-bit UID (Exception: Solaris - all
UIDs are 32-bit)
PROBLEM
Normally many NFS implementations request that the UID presented
to them are 16-bit UIDs (User IDs). However, if you present them
with a 32-bit UID where the lower order (the numbers farthest to
the right) bits are set to 0, the UID gets interpreted as root on
the server with 16-bit UIDs.
Any user with 32-bit UIDs where the lower numbers are set to 0 can
read/write any files owned by root
SOLUTION
Get patch #1095935 from Sun