The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade quota | Dec 1, 2016 | Aug 13, 2012 |
| Debian | — | Upgrade quota | Jul 30, 2024 | Aug 13, 2012 |
| Oracle_linux | — | Upgrade quota | Oct 16, 2024 | Aug 13, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 22, 2009 |
| Suse | — | Upgrade quota-nfsUpgrade quota | Dec 12, 2013 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub