Linux nfsd Remote Buffer Overflow Vulnerability
BID:782
Info
Linux nfsd Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 782 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 09 1999 12:00AM |
| Updated: | Nov 09 1999 12:00AM |
| Credit: | This was posted to BugTraq by Mariusz Marcinkiewicz <[email protected]> on Nov 9, 1999. |
| Vulnerable: |
Redhat Linux 5.2 i386 Debian Linux 2.1 |
| Not Vulnerable: |
Redhat Linux 6.0 Debian Linux 2.2 |
Discussion
Linux nfsd Remote Buffer Overflow Vulnerability
A remotely exploitable buffer overflow vulnerability was found in versions of Linux nfsd known to ship with Debian Linux 2.1 and RedHat Linux 5.2. When they were fixed in the respective distributions/versions, no vulnerability information was published by the vendors. The vulnerability was in removal of long directory paths on a mounted nfs share. The length of the string holding the directory name which was to be removed was not checked and the buffer holding it could be overflowed, allowing execution of arbitrary code on the nfs server as root. A consequence of this being exploited is remote root compromise.
A remotely exploitable buffer overflow vulnerability was found in versions of Linux nfsd known to ship with Debian Linux 2.1 and RedHat Linux 5.2. When they were fixed in the respective distributions/versions, no vulnerability information was published by the vendors. The vulnerability was in removal of long directory paths on a mounted nfs share. The length of the string holding the directory name which was to be removed was not checked and the buffer holding it could be overflowed, allowing execution of arbitrary code on the nfs server as root. A consequence of this being exploited is remote root compromise.
Exploit / POC
Linux nfsd Remote Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not ware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not ware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Linux nfsd Remote Buffer Overflow Vulnerability
Solution:
A temporary solution is to remove the setuid bit from nfsd and/or stop the nfsd service.
A more long term solution is to upgrade to the newest version of nfsd for linux, since this has been fixed.
Slackware 4.0:
ftp.cdrom.com:/pub/linux/slackware-4.0/patches/nfs-server.tgz
Slackware 7.0:
ftp.cdrom.com:/pub/linux/slackware-7.0/patches/nfs-server.tgz
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
A temporary solution is to remove the setuid bit from nfsd and/or stop the nfsd service.
A more long term solution is to upgrade to the newest version of nfsd for linux, since this has been fixed.
Slackware 4.0:
ftp.cdrom.com:/pub/linux/slackware-4.0/patches/nfs-server.tgz
Slackware 7.0:
ftp.cdrom.com:/pub/linux/slackware-7.0/patches/nfs-server.tgz
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Linux nfsd Remote Buffer Overflow Vulnerability
References:
References:
- Debian Security Information (Debian GNU/Linux)
- Updates, Fixes, and Errata Page (RedHat)