The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroups and allows remote attackers to bypass intended access restrictions.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade nfs-utils | Dec 1, 2016 | Oct 14, 2008 |
| Debian | — | Upgrade nfs-utils | Jul 30, 2024 | Oct 14, 2008 |
| Gentoo Linux | — | Upgrade net-fs/nfs-utils. | Oct 30, 2017 | Oct 14, 2008 |
| Oracle_linux | — | Upgrade nfs-utils | Oct 16, 2024 | Oct 14, 2008 |
| Suse | — | Upgrade nfs-utils | Feb 17, 2015 | Oct 14, 2008 |
| Ubuntu | — | Upgrade nfs-kernel-server | Nov 8, 2024 | Oct 14, 2008 |
| Vmsa 2010 0004 2 Vma And Service Console Update | — | Upgrade VMware ESX 4.0 to build number 236512 | Aug 31, 2010 | Oct 14, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub