Updated nfs-utils packages are available that fix a remotely exploitable Denial of Service vulnerability. [Updated 30 July 2003] Added packages for Red Hat Linux on IBM iSeries and pSeries systems.
The nfs-utils package provides a daemon for the kernel NFS server and related tools. Janusz Niewiadomski found a buffer overflow bug in nfs-utils version 1.0.3 and earlier. This bug could be exploited by an attacker, causing a remote Denial of Service (crash). It is not believed that this bug could lead to remote arbitrary code execution. Users are advised to update to these erratum packages, which contain a backported security patch supplied by the nfs-utils maintainers and are not vulnerable to this issue.