PT-2014-1909 · Nfs Utils+1 · Nfs-Utils+1
Vincent Danen
·
Publicado
2013-05-22
·
Atualizado
2017-08-29
·
CVE-2013-1923
CVSS v2.0
3.2
Baixa
| Vetor | AV:A/AC:H/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
nfs-utils versions prior to 1.2.8
Description
The issue concerns a problem with rpc-gssd in nfs-utils, where it performs reverse DNS resolution for server names during GSSAPI authentication. This could potentially allow remote attackers to read otherwise-restricted files via DNS spoofing attacks, leading to a breach of confidentiality and integrity of protected information.
Recommendations
For versions prior to 1.2.8, update to version 1.2.8 or later to resolve the issue. As a temporary workaround, consider restricting DNS resolution for server names during GSSAPI authentication to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Suse
Nfs-Utils