Rapid7 Vulnerability & Exploit Database

Multiple Vendor Statd Buffer Overflow Vulnerability

Free InsightVM Trial No credit card necessary
Watch Demo See how it all works
Back to Search

Multiple Vendor Statd Buffer Overflow Vulnerability

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
12/05/1997
Created
07/25/2018
Added
11/01/2004
Modified
12/04/2013

Description

Statd is the RPC NFS status daemon. It is used to communicate status information to other services or host.

The version of statd shipped with many unix implementations contains a buffer overflow condition. This overflow condition exists in the handling of 'SM_MON' RPC requests. Any attacker to successfully exploit this vulnerability would gain root privileges on the target host.

Solution(s)

  • nfs-statd-0001

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;