The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does...
Vulnerability Description
The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-2500
Credits & Attribution
No credits recorded in the NVD database.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=716949
- http://sourceforge.net/projects/nfs/files/nfs-utils/1.2.4/Changelog-nfs-utils-1.2.4/download
- http://marc.info/?l=linux-nfs&m=130875695821953&w=2
- http://rhn.redhat.com/errata/RHSA-2011-1534.html
- http://sourceforge.net/projects/nfs/files/nfs-utils/1.2.4/
More from linux-nfs
View All →Affected Vendor
linux-nfs
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.