PT-2014-1909 · Nfs Utils+1 · Nfs-Utils+1

Vincent Danen

·

Published

2013-05-22

·

Updated

2017-08-29

·

CVE-2013-1923

CVSS v2.0

3.2

Low

VectorAV:A/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions nfs-utils versions prior to 1.2.8
Description The issue concerns a problem with rpc-gssd in nfs-utils, where it performs reverse DNS resolution for server names during GSSAPI authentication. This could potentially allow remote attackers to read otherwise-restricted files via DNS spoofing attacks, leading to a breach of confidentiality and integrity of protected information.
Recommendations For versions prior to 1.2.8, update to version 1.2.8 or later to resolve the issue. As a temporary workaround, consider restricting DNS resolution for server names during GSSAPI authentication to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09773
CVE-2013-1923
MGASA-2013-0178
SUSE-SU-2013_0821-1
SUSE-SU-2013_0822-1
SUSE-SU-2013_1668-1

Affected Products

Suse
Nfs-Utils