PT-2011-3339 · Freebsd · Freebsd

Ruslan Ermilov

·

Publicado

2011-05-03

·

Atualizado

2017-08-17

·

CVE-2011-1739

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FreeBSD versions 7.4 through 8.2
Description The issue arises from the makemask function in mountd.c, which does not correctly handle a -network field specifying a CIDR block with a prefix length that is not an integer multiple of 8. This allows remote attackers to bypass intended access restrictions under certain circumstances via an NFS mount request.
Recommendations For FreeBSD versions 7.4 through 8.2, update to a version that includes a fix for the makemask function issue in mountd.c to prevent remote attackers from bypassing access restrictions.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1739

Produtos afetados

Freebsd