Vulnerability CVE-2011-2500: Information

Description

The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.

Severity: HIGH (7.5)

Published: Feb. 15, 2014
Modified: March 6, 2014
Error type identifier: CWE-264

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:linux-nfs:nfs-utils:*:*:*:*:*:*:*:*
      End including
      1.2.3

      cpe:2.3:a:linux-nfs:nfs-utils:1.2.2:*:*:*:*:*:*:*

      cpe:2.3:a:linux-nfs:nfs-utils:1.2.1:*:*:*:*:*:*:*

      cpe:2.3:a:linux-nfs:nfs-utils:1.2.0:*:*:*:*:*:*:*