Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Hpux | — | Update NFS.KEY-CORE to the latest versionUpdate NFS.NIS-CORE to the latest versionUpdate NFS.NFS-SERVER to the latest versionUpdate NFS.NFS-CLIENT to the latest versionUpdate NFS.NFS-PRG to the latest versionUpdate NFS.NIS-CLIENT to the latest versionUpdate NFS.NFS-64ALIB to the latest versionApply patch PHNE_41021 from HPUpdate NFS.NFS2-CLIENT to the latest versionApply patch PHNE_41023 from HPUpdate NFS.NIS-SERVER to the latest versionUpdate NFS.NFS-SHLIBS to the latest versionUpdate NFS.NFS2-SERVER to the latest versionUpdate NFS.NFS2-CORE to the latest versionUpdate NFS.NFS-CORE to the latest versionUpdate NFS.NFS-KRN to the latest versionUpdate NFS.NFS-64SLIB to the latest versionUpdate NFS.NFS2-PRG to the latest versionUpdate NFS.NIS2-CLIENT to the latest version | Aug 11, 2017 | May 20, 2010 |
| Ibm Aix | — | Apply the fix or workaround for pcnfsd_advisory | Nov 30, 2017 | May 20, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub