Back to search
CVE-2011-2500
Published: Feb 15, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.redhat.com/show_bug.cgi?id=716949
x_refsource_CONFIRM
[linux-nfs] 20110622 [PATCH] nfs: fix host_reliable_addrinfo (try #2)
mailing-list
x_refsource_MLIST
RHSA-2011:1534
vendor-advisory
x_refsource_REDHAT
http://sourceforge.net/projects/nfs/files/nfs-utils/1.2.4/
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now