Description
rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.
Affected products
- nfs / nfs-utils1.0 – 1.0
- nfs / nfs-utils1.0.1 – 1.0.1
- nfs / nfs-utils1.0.3 – 1.0.3
- nfs / nfs-utils1.0.4 – 1.0.4
- nfs / nfs-utils1.0.6 – 1.0.6
References
- MISChttp://www.trustix.org/errata/misc/2004/TSL-2004-0009-nfs-utils.asc.txt
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9673
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A861
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/15418
- MISChttp://www.securityfocus.com/bid/9813
- MISChttp://bugzilla.redhat.com/bugzilla/long_list.cgi?buglist=114535
- MISChttp://www.redhat.com/support/errata/RHSA-2004-072.html