PT-2010-3640 · Freebsd · Freebsd

Argp

+1

·

Publicado

2010-05-28

·

Atualizado

2012-11-06

·

CVE-2010-2020

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeBSD versions 7.2 through 8.1-PRERELEASE
Description The issue concerns a lack of validation for the length of a certain fhsize parameter in the NFS client, specifically in the sys/nfsclient/nfs vfsops.c file. This allows local users to gain privileges via a crafted mount request when vfs.usermount is enabled.
Recommendations For FreeBSD versions 7.2 through 8.1-PRERELEASE, consider disabling the vfs.usermount option to minimize the risk of exploitation until a patch is available.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2020

Produtos afetados

Freebsd