PT-2014-1909 · Nfs Utils+1 · Nfs-Utils+1

Vincent Danen

·

Publicado

2013-05-22

·

Atualizado

2017-08-29

·

CVE-2013-1923

CVSS v2.0

3.2

Baixa

VetorAV:A/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions nfs-utils versions prior to 1.2.8
Description The issue concerns a problem with rpc-gssd in nfs-utils, where it performs reverse DNS resolution for server names during GSSAPI authentication. This could potentially allow remote attackers to read otherwise-restricted files via DNS spoofing attacks, leading to a breach of confidentiality and integrity of protected information.
Recommendations For versions prior to 1.2.8, update to version 1.2.8 or later to resolve the issue. As a temporary workaround, consider restricting DNS resolution for server names during GSSAPI authentication to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09773
CVE-2013-1923
MGASA-2013-0178
SUSE-SU-2013_0821-1
SUSE-SU-2013_0822-1
SUSE-SU-2013_1668-1

Produtos afetados

Suse
Nfs-Utils