Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2019-3689
Disclosure Date: September 19, 2019 (last updated November 08, 2023)
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.
0
Attacker Value
Unknown
CVE-2011-1749
Disclosure Date: February 26, 2014 (last updated October 05, 2023)
The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
0
Attacker Value
Unknown
CVE-2011-2500
Disclosure Date: February 15, 2014 (last updated October 05, 2023)
The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.
0
Attacker Value
Unknown
CVE-2013-1923
Disclosure Date: January 21, 2014 (last updated October 05, 2023)
rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks.
0
Attacker Value
Unknown
CVE-2009-0180
Disclosure Date: January 20, 2009 (last updated October 04, 2023)
Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions, possibly a related issue to CVE-2008-1376.
0
Attacker Value
Unknown
CVE-2008-4552
Disclosure Date: October 14, 2008 (last updated October 04, 2023)
The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroups and allows remote attackers to bypass intended access restrictions.
0
Attacker Value
Unknown
CVE-2008-1376
Disclosure Date: August 01, 2008 (last updated October 04, 2023)
A certain Red Hat build script for nfs-utils before 1.0.9-35z.el5_2 on Red Hat Enterprise Linux (RHEL) 5 omits TCP wrappers support, which might allow remote attackers to bypass intended access restrictions.
0
Attacker Value
Unknown
CVE-2004-0946
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attackers to execute arbitrary code via a crafted NFS request.
0
Attacker Value
Unknown
CVE-2004-1014
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
0
Attacker Value
Unknown
CVE-2004-0154
Disclosure Date: June 14, 2004 (last updated February 22, 2025)
rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.
0