RedHat Linux nfs-server Vulnerabilities
BID:483
Info
RedHat Linux nfs-server Vulnerabilities
| Bugtraq ID: | 483 |
| Class: | Unknown |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Jun 24 1999 12:00AM |
| Updated: | Jun 24 1999 12:00AM |
| Credit: | First made public in RedHat Linux security advisory RHSA-1999:016-01, released on June 24, 1999. |
| Vulnerable: |
Redhat Linux 5.2 i386 |
| Not Vulnerable: | |
Discussion
RedHat Linux nfs-server Vulnerabilities
There were a few potential security vulnerabilities in the nfs server package shipped with RedHat Linux 5.2. They were a result of the type uid_t being changed to a 32 bit value in glibc 2.0.x. This affected the ability of the suid root binaries involved to drop effective userid properly. Exact details of this vulnerability are unknown at this time.
There were a few potential security vulnerabilities in the nfs server package shipped with RedHat Linux 5.2. They were a result of the type uid_t being changed to a 32 bit value in glibc 2.0.x. This affected the ability of the suid root binaries involved to drop effective userid properly. Exact details of this vulnerability are unknown at this time.
Exploit / POC
RedHat Linux nfs-server Vulnerabilities
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RedHat Linux nfs-server Vulnerabilities
Solution:
As this was addressed in a RedHat Linux security advisory, fixed upgrades are available at the following location:
Intel: ftp://updates.redhat.com/5.2/i386
nfs-server-2.2beta44.i386.rpm
nfs-server-clients2.2beta44.i386.rpm
Alpha: ftp://updates.redhat.com/5.2/alpha
nfs-server-2.2beta44.alpha.rpm
nfs-server-clients-2.2beta44.alpha.rpm
Sparc: ftp://updates.redhat.com/5.2/sparc
nfs-server-2.2beta44.sparc.rpm
nfs-server-clients-2.2beta44.sparc.rpm
Solution:
As this was addressed in a RedHat Linux security advisory, fixed upgrades are available at the following location:
Intel: ftp://updates.redhat.com/5.2/i386
nfs-server-2.2beta44.i386.rpm
nfs-server-clients2.2beta44.i386.rpm
Alpha: ftp://updates.redhat.com/5.2/alpha
nfs-server-2.2beta44.alpha.rpm
nfs-server-clients-2.2beta44.alpha.rpm
Sparc: ftp://updates.redhat.com/5.2/sparc
nfs-server-2.2beta44.sparc.rpm
nfs-server-clients-2.2beta44.sparc.rpm
References
RedHat Linux nfs-server Vulnerabilities
References:
References: