|
|
Info |
Last Modified |
| 7 months ago |
|
|
|
|
Description |
The rpc.statd program contained in the nfs-utils package contains a flaw that may allow a malicious user to gain remote root access. The issue is triggered when raw user input is passed to the syslog() function. It is possible that the flaw may allow arbitrary code exectuion resulting in a loss of integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Technical |
The rpc.statd program included with the nfs-utils package passes user-supplied data to the syslog() function resulting in a possible remote format string attack.
|
|
Solution |
Upgrade to the latest version of RPC statd. Contact your vendor for upgrade information.
|
|
Products |
|
nfs-utils
 |
0.1.8.2 |
0.1.8 |
0.1.7 |
|
|
|
|
|
|
Credit |
- Daniel Jacobowitz - drow
false.org -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|