NFS-Utils Xlog Remote Buffer Overrun Vulnerability
BID:8179
Info
NFS-Utils Xlog Remote Buffer Overrun Vulnerability
| Bugtraq ID: | 8179 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0252 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery is credited to Janusz Niewiadomski. |
| Vulnerable: |
Sun Cobalt RaQ4 3001R Sun Cobalt RaQ XTR SCO OpenLinux Workstation 3.1.1 SCO OpenLinux Server 3.1.1 nfs nfs-utils 1.0.3 nfs nfs-utils 1.0.1 nfs nfs-utils 1.0 nfs nfs-utils 0.3.3 nfs nfs-utils 0.3.1 nfs nfs-utils 0.2.1 nfs nfs-utils 0.2 |
| Not Vulnerable: |
nfs nfs-utils 1.0.4 |
Discussion
NFS-Utils Xlog Remote Buffer Overrun Vulnerability
A remote exploitable buffer overrun vulnerability has been reported in the xlog component of nfs-utils. It is possible to exploit this issue via mountd. It has been reported that exploitation of this issue will most likely result in a denial of service. There is a possibility that this issue could be exploited to run arbitrary code in the context of mountd, which runs as root.
A remote exploitable buffer overrun vulnerability has been reported in the xlog component of nfs-utils. It is possible to exploit this issue via mountd. It has been reported that exploitation of this issue will most likely result in a denial of service. There is a possibility that this issue could be exploited to run arbitrary code in the context of mountd, which runs as root.
References
NFS-Utils Xlog Remote Buffer Overrun Vulnerability
References:
References:
- nfs Homepage (nfs)
- RHSA-2003:206-08 Updated nfs-utils packages fix denial of service vulnerability (Red Hat)
- Sun Alert ID: 55882 (Sun Microsystems)
- Sun Cobalt RaQ 4 Patches (Sun)
- Sun Cobalt RaQ XTR Patches (Sun)
- YDU-20030718-1 Updated nfs-utils packages are available. (Yellow Dog)
- Linux nfs-utils xlog() off-by-one bug (Janusz Niewiadomski
)