Back to Database
Status published
Medium
CVE-2004-1014
statd in nfs-utils 1.257 and earlier does not ignore the...
Vulnerability Description
statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-1014
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.debian.org/security/2004/dsa-606
- http://www.redhat.com/support/errata/RHSA-2005-014.html
- http://www.redhat.com/support/errata/RHSA-2004-583.html
- http://www.securityfocus.com/bid/11785
- http://cvs.sourceforge.net/viewcvs.py/nfs/nfs-utils/ChangeLog?rev=1.258&view=markup
- http://www.securityfocus.com/archive/1/426072/30/6740/threaded
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10899
- https://www.ubuntu.com/usn/usn-36-1/
- http://www.trustix.org/errata/2004/0065/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18332
More from nfs
View All →CVE-2009-0180
Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora...
High
7.5
CVE-2008-4552
The good_client function in nfs-utils 1.0.9, and possibly other versions...
High
7.5
CVE-2004-0946
rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does...
Critical
10
CVE-2004-0154
rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers...
Medium
5
Affected Vendor
Affected Software
nfs-utils, debian linux, mandrake linux, mandrake linux corporate server, enterprise linux, enterprise linux desktop
Vulnerable Versions:
1.0.6, 3.0, 9.2, 10.0, 10.1, 2.1
Timeline
Official Publish:
December 8th, 2004
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.