The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nfs-utils | Jul 30, 2024 | Feb 15, 2014 |
| Oracle_linux | — | Upgrade nfs-utils | Oct 16, 2024 | Feb 15, 2014 |
| Suse | — | Upgrade nfs-docUpgrade nfs-clientUpgrade nfs-kernel-server | Dec 12, 2013 | Dec 10, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub