PT-2011-3339 · Freebsd · Freebsd
Ruslan Ermilov
·
Published
2011-05-03
·
Updated
2017-08-17
·
CVE-2011-1739
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FreeBSD versions 7.4 through 8.2
Description
The issue arises from the makemask function in mountd.c, which does not correctly handle a -network field specifying a CIDR block with a prefix length that is not an integer multiple of 8. This allows remote attackers to bypass intended access restrictions under certain circumstances via an NFS mount request.
Recommendations
For FreeBSD versions 7.4 through 8.2, update to a version that includes a fix for the makemask function issue in mountd.c to prevent remote attackers from bypassing access restrictions.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd