PT-2012-4698 · Linux+2 · Linux Diskquota+2

Tomas Hoger

·

Published

2012-08-13

·

Updated

2023-02-13

·

CVE-2012-3417

CVSS v2.0

4.0

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Linux DiskQuota (aka quota) versions prior to 3.17
Description The issue concerns the good client function in rquotad, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny. This occurs because the hosts ctl function is invoked without a host name.
Recommendations For versions prior to 3.17, update to version 3.17 or later to resolve the issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2012-3417
RHSA-2013:0120
RHSA-2013_0120
SUSE-SU-2012_1071-1
SUSE-SU-2012_1071-2

Affected Products

Linux Diskquota
Red Hat
Suse