PT-2003-2525 · Linux · Nfs-Utils

Janusz Niewiadomski

·

Published

1970-01-01

·

Updated

2024-02-02

·

CVE-2003-0252

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions nfs-utils versions prior to 1.0.4
Description The issue is caused by an off-by-one error in the xlog function of mountd in the Linux NFS utils package. This error allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines. The vulnerability can be exploited remotely, potentially leading to a disruption of confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the mountd service to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2015-02020
BDU:2015-02021
BDU:2015-04794
BDU:2015-08173
CVE-2003-0252
DSA-349

Affected Products

Nfs-Utils