|
|
|
![]() |
Vulnerability Note VU#698302nfs-utils vulnerable to buffer overflow in "getquotainfo()" in "rquota_server.c"OverviewA vulnerability in nfs-utils could permit an attacker to execute arbitrary code on the system or cause a denial of service.I. DescriptionThe NFS protocol provides remote access to shared files accross networks. The nfs-utils package provides an NFS client and server for Linux systems. Nfs-utils on 64-bit architecture machines contains a stack-based buffer overflow vulnerability. The function "getquotainfo()" in "rquota_server.c" assumes certain values to be 32-bit in size during a call to memcpy(). On a 64-bit machine, this can cause a buffer overflow.II. ImpactA remote attacker could execute arbitrary code or create a denial-of-service condition on a vulnerable server running nfs-utils.III. SolutionApply a patch from your vendorFor vendor-specific information regarding vulnerable status and patch availability, please see the vendor section of this document.
References
Red Hat credits Arjan van de Ven with reporting this vulnerability. This document was written by Will Dormann.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||