Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Argp

#39593of 53,612
6.9Total CVSS
Vulnerabilities · 1
PT-2010-3640
6.9
2010-05-28
Freebsd · Freebsd · CVE-2010-2020
**Name of the Vulnerable Software and Affected Versions** FreeBSD versions 7.2 through 8.1-PRERELEASE **Description** The issue concerns a lack of validation for the length of a certain `fhsize` parameter in the NFS client, specifically in the `sys/nfsclient/nfs vfsops.c` file. This allows local users to gain privileges via a crafted mount request when `vfs.usermount` is enabled. **Recommendations** For FreeBSD versions 7.2 through 8.1-PRERELEASE, consider disabling the `vfs.usermount` option to minimize the risk of exploitation until a patch is available.