PT-2011-3339 · Freebsd · Freebsd

Ruslan Ermilov

·

Published

2011-05-03

·

Updated

2017-08-17

·

CVE-2011-1739

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FreeBSD versions 7.4 through 8.2
Description The issue arises from the makemask function in mountd.c, which does not correctly handle a -network field specifying a CIDR block with a prefix length that is not an integer multiple of 8. This allows remote attackers to bypass intended access restrictions under certain circumstances via an NFS mount request.
Recommendations For FreeBSD versions 7.4 through 8.2, update to a version that includes a fix for the makemask function issue in mountd.c to prevent remote attackers from bypassing access restrictions.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1739

Affected Products

Freebsd