The NFSv4 ID mapper (nfsidmap) before 0.17 does not properly...
Vulnerability Description
The NFSv4 ID mapper (nfsidmap) before 0.17 does not properly handle return values from the getpwnam_r function when performing a username lookup, which can cause it to report a file as being owned by "root" instead of "nobody" if the file exists on the server but not on the client.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-4135
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/27043
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9864
- http://www.redhat.com/support/errata/RHSA-2007-0951.html
- http://www.novell.com/linux/security/advisories/2007_18_sr.html
- http://www.securityfocus.com/bid/26767
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:240
- http://osvdb.org/45825
- http://secunia.com/advisories/26674
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36396
Affected Vendor
nfsv4
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.