Linux NFS RPC.STATD Remote Denial Of Service Vulnerability
BID:11785
Info
Linux NFS RPC.STATD Remote Denial Of Service Vulnerability
| Bugtraq ID: | 11785 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-1014 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2004 12:00AM |
| Updated: | Dec 14 2006 06:44PM |
| Credit: | This vulnerability was disclosed by SGI. |
| Vulnerable: |
Turbolinux Turbolinux Workstation 8.0 Turbolinux Turbolinux Workstation 7.0 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 7.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Home Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 3 Redhat Desktop 3.0 nfs nfs-utils 1.0.6 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 Mandriva Linux Mandrake 9.2 amd64 Mandriva Linux Mandrake 9.2 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
Linux NFS RPC.STATD Remote Denial Of Service Vulnerability
It is reported that 'rpc.statd' is vulnerable to a remote denial-of-service vulnerability.
This vulnerability allows remote attackers to crash the affected application. This may result in the failure to clean up NFS network locks, possibly resulting in denied access to files, because they may be considered permanently locked.
Version 1.0.6 of nfs-utils is reported vulnerable to this issue. Other versions may also be affected.
It is reported that 'rpc.statd' is vulnerable to a remote denial-of-service vulnerability.
This vulnerability allows remote attackers to crash the affected application. This may result in the failure to clean up NFS network locks, possibly resulting in denied access to files, because they may be considered permanently locked.
Version 1.0.6 of nfs-utils is reported vulnerable to this issue. Other versions may also be affected.
Exploit / POC
Linux NFS RPC.STATD Remote Denial Of Service Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Linux NFS RPC.STATD Remote Denial Of Service Vulnerability
Solution:
Please see the referenced vendor advisories for further information.
nfs nfs-utils 1.0.6
Solution:
Please see the referenced vendor advisories for further information.
nfs nfs-utils 1.0.6
-
Mandrake nfs-utils-1.0.6-2.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake nfs-utils-1.0.6-2.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake nfs-utils-1.0.6-2.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake nfs-utils-1.0.6-2.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake nfs-utils-clients-1.0.6-2.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake nfs-utils-clients-1.0.6-2.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake nfs-utils-clients-1.0.6-2.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake nfs-utils-clients-1.0.6-2.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
RedHat nfs-utils-1.0.6-1.2.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/nfs-utils-1.0.6 -1.2.legacy.i386.rpm -
RedHat nfs-utils-1.0.6-22.2.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/nfs-utils-1.0.6 -22.2.legacy.i386.rpm -
RedHat nfs-utils-1.0.6-1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/nfs-utils-1.0.6 -1.1.legacy.i386.rpm -
Trustix nfs-utils-1.0.6-4tr.i586.rpm
This fix should be retrieved for the relevant Trustix platform:
http://www.trustix.org/download/ -
TurboLinux nfs-utils-1.0.6-13.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/nfs-utils-1.0.6-13.i586.rpm -
TurboLinux nfs-utils-1.0.6-13.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/10/up dates/RPMS/nfs-utils-1.0.6-13.i586.rpm -
Ubuntu nfs-common_1.0.6-3ubuntu1.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/nfs-utils/nfs-common_1.0 .6-3ubuntu1.1_amd64.deb -
Ubuntu nfs-common_1.0.6-3ubuntu1.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/nfs-utils/nfs-common_1.0 .6-3ubuntu1.1_i386.deb -
Ubuntu nfs-common_1.0.6-3ubuntu1.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/nfs-utils/nfs-common_1.0 .6-3ubuntu1.1_powerpc.deb -
Ubuntu nfs-kernel-server_1.0.6-3ubuntu1.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/nfs-utils/nfs-kernel-ser ver_1.0.6-3ubuntu1.1_amd64.deb -
Ubuntu nfs-kernel-server_1.0.6-3ubuntu1.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/nfs-utils/nfs-kernel-ser ver_1.0.6-3ubuntu1.1_i386.deb -
Ubuntu nfs-kernel-server_1.0.6-3ubuntu1.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/n/nfs-utils/nfs-kernel-ser ver_1.0.6-3ubuntu1.1_powerpc.deb -
Ubuntu nhfsstone_1.0.6-3ubuntu1.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/n/nfs-utils/nhfsstone_ 1.0.6-3ubuntu1.1_amd64.deb -
Ubuntu nhfsstone_1.0.6-3ubuntu1.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/n/nfs-utils/nhfsstone_ 1.0.6-3ubuntu1.1_i386.deb -
Ubuntu nhfsstone_1.0.6-3ubuntu1.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/universe/n/nfs-utils/nhfsstone_ 1.0.6-3ubuntu1.1_powerpc.deb
References
Linux NFS RPC.STATD Remote Denial Of Service Vulnerability
References:
References: