Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown

CVE-2008-4552

Disclosure Date: October 14, 2008 (last updated October 04, 2023)
The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroups and allows remote attackers to bypass intended access restrictions.
0
Attacker Value
Unknown

CVE-2007-4135

Disclosure Date: September 05, 2007 (last updated October 04, 2023)
The NFSv4 ID mapper (nfsidmap) before 0.17 does not properly handle return values from the getpwnam_r function when performing a username lookup, which can cause it to report a file as being owned by "root" instead of "nobody" if the file exists on the server but not on the client.
0
Attacker Value
Unknown

CVE-2004-0946

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attackers to execute arbitrary code via a crafted NFS request.
0
Attacker Value
Unknown

CVE-2004-1014

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
0
Attacker Value
Unknown

CVE-2004-0154

Disclosure Date: June 14, 2004 (last updated February 22, 2025)
rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.
0
Attacker Value
Unknown

CVE-2003-0252

Disclosure Date: August 18, 2003 (last updated February 22, 2025)
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.