PT-2000-1008 · Nfs Utils · Nfs-Utils
Published
2000-07-16
·
Updated
2018-05-03
·
CVE-2000-0666
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
nfs-utils versions 0.1.9.1 and earlier
Description
The issue is related to the rpc.statd in the nfs-utils package, which does not properly cleanse untrusted format strings. This allows remote attackers to gain root privileges, potentially leading to a breach of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations
For nfs-utils version 0.1.9.1 and earlier, consider updating to a newer version that addresses this issue, although the specific fixed version is not provided in the available data. As a temporary workaround, consider restricting access to the rpc.statd service to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nfs-Utils