Multiple Vendor rpc.mountd File Disclosure Vulnerablity

BID:95

Info

Multiple Vendor rpc.mountd File Disclosure Vulnerablity

Bugtraq ID: 95
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Aug 24 1997 12:00AM
Updated: Aug 24 1997 12:00AM
Credit: Announced by Peter Jones <[email protected]>.
Vulnerable: Sun Solaris 2.5.1 _x86
Sun Solaris 2.5.1
Sun Solaris 2.6_x86
Sun Solaris 2.6
Sun Solaris 2.5_x86
Sun Solaris 2.5
Sun Solaris 2.4_x86
Sun Solaris 2.4
Sun Solaris 2.3
SGI IRIX 6.5.22
SGI IRIX 6.5.21 m
SGI IRIX 6.5.21 f
SGI IRIX 6.5.20 m
SGI IRIX 6.5.20 f
SGI IRIX 6.5.19 m
SGI IRIX 6.5.19 f
SGI IRIX 6.5.18 m
SGI IRIX 6.5.18 f
SGI IRIX 6.5.17 m
SGI IRIX 6.5.17 f
SGI IRIX 6.5.16
SGI IRIX 6.5.15
SGI IRIX 6.5.14
SGI IRIX 6.5.13
SGI IRIX 6.5.12
SGI IRIX 6.5.11
SGI IRIX 6.5.10
SGI IRIX 6.5.9
SGI IRIX 6.5.8
SGI IRIX 6.5.7
SGI IRIX 6.5.6
SGI IRIX 6.5.5
SGI IRIX 6.5.4
SGI IRIX 6.5.3
SGI IRIX 6.5.2
SGI IRIX 6.5.1
SGI IRIX 6.5
HP HP-UX 11.22
HP HP-UX 11.11
HP HP-UX 11.0
Caldera OpenLinux Standard 1.1
Caldera OpenLinux Standard 1.0
Caldera OpenLinux Lite 1.1
Caldera OpenLinux Lite 1.0
Caldera OpenLinux Base 1.1
Caldera OpenLinux Base 1.0
Caldera OpenLinux 1.1
Caldera OpenLinux 1.0
Caldera Network Desktop 1.0
Not Vulnerable:

Discussion

Multiple Vendor rpc.mountd File Disclosure Vulnerablity

rpc.mountd is an RPC server that handles NFS file system mount requests. A vulnerability has been discovered with mountd which, if exploited, allows the attacker to obtain information about any file that exists on the NFS server. This is possible for files that are not a part of the NFS exported file system.

Exploit / POC

Multiple Vendor rpc.mountd File Disclosure Vulnerablity

There is no exploit code required. An attacker needs only NFS client software.

Solution / Fix

Multiple Vendor rpc.mountd File Disclosure Vulnerablity

Solution:
Patches are available to all Sun customers at http://sunsolve.sun.com.

Caldera has made patches available in their advisory:

ftp://ftp.caldera.com/pub/security/OpenLinux/SA-1997.17.txt

HP has issued fixes in advisory HPSBUX0308-272. HP has released a revised version of this advisory that corrects a fix that was issued in the original advisory. Please see the most recent version of the advisory for details on obtaining fixes.

SGI has released an updated security advisory (20031102-02-P) including patches to address this issue. This advisory includes updated patches 5426-5429 to address a mismatch between exportfs and rpc.mountd that was introduced in the previous patches. Please see the revised advisory for further information.

Revised HP advisory HPSBUX0308-272 is available.


Sun Solaris 2.5_x86

Sun Solaris 2.4

Sun Solaris 2.4_x86

Sun Solaris 2.6_x86

Sun Solaris 2.5
  • Sun 104223-02
    sparc


Sun Solaris 2.6

Sun Solaris 2.3
  • Sun 102654-02
    sparc


Sun Solaris 2.5.1

Sun Solaris 2.5.1 _x86

References

Multiple Vendor rpc.mountd File Disclosure Vulnerablity

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report