|
|
Info |
Last Modified |
| 7 months ago |
|
|
|
|
Description |
nfs-utils contains a flaw that allows a remote attacker to gain root privileges. The issue is due to a buffer overflow caused by an off-by-one error in the "xlog" function. If an attacker creates a specially crafted RPC request to the rpc.mountd daemon they may be able to execute arbitrary code.
|
|
Classification |
Location:
Local Access Required,
Remote/Network Access Required
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unavailable
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to version 1.0.4 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
nfs-utils
 |
1.0.1 |
1.0.2 |
1.0.3 |
|
|
|
|
|
|
Credit |
- Janusz Niewiadomski - funkysh
isec.pl - Isec
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|