PT-2000-1008 · Nfs Utils · Nfs-Utils

Published

2000-07-16

·

Updated

2018-05-03

·

CVE-2000-0666

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions nfs-utils versions 0.1.9.1 and earlier
Description The issue is related to the rpc.statd in the nfs-utils package, which does not properly cleanse untrusted format strings. This allows remote attackers to gain root privileges, potentially leading to a breach of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations For nfs-utils version 0.1.9.1 and earlier, consider updating to a newer version that addresses this issue, although the specific fixed version is not provided in the available data. As a temporary workaround, consider restricting access to the rpc.statd service to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07894
CVE-2000-0666

Affected Products

Nfs-Utils