CVE-2003-0252
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 15.78% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-193
- Affected
- linux-nfs/nfs-utils
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0023.htmlBroken Link, Vendor Advisory
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0024.htmlBroken Link, Vendor Advisory
- http://isec.pl/vulnerabilities/isec-0010-linux-nfs-utils.txtExploit, Third Party Advisory
- http://marc.info/?l=bugtraq&m=105820223707191&w=2Exploit, Mailing List
- http://marc.info/?l=bugtraq&m=105830921519513&w=2Mailing List, Patch
- http://marc.info/?l=bugtraq&m=105839032403325&w=2Mailing List
- http://secunia.com/advisories/9259Broken Link
- http://securitytracker.com/id?1007187Broken Link, Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001262.1-1Broken Link
- http://www.debian.org/security/2003/dsa-349Broken Link
- http://www.kb.cert.org/vuls/id/258564Third Party Advisory, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:076Third Party Advisory
- http://www.novell.com/linux/security/advisories/2003_031_nfs_utils.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-206.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2003-207.htmlBroken Link
- http://www.securityfocus.com/bid/8179Broken Link, Third Party Advisory, VDB Entry
- http://www.turbolinux.com/security/TLSA-2003-44.txtBroken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/12600Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A443Broken Link
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0023.htmlBroken Link, Vendor Advisory
- http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0024.htmlBroken Link, Vendor Advisory
- http://isec.pl/vulnerabilities/isec-0010-linux-nfs-utils.txtExploit, Third Party Advisory
- http://marc.info/?l=bugtraq&m=105820223707191&w=2Exploit, Mailing List
- http://marc.info/?l=bugtraq&m=105830921519513&w=2Mailing List, Patch
- http://marc.info/?l=bugtraq&m=105839032403325&w=2Mailing List
- http://secunia.com/advisories/9259Broken Link
- http://securitytracker.com/id?1007187Broken Link, Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1001262.1-1Broken Link
- http://www.debian.org/security/2003/dsa-349Broken Link
- http://www.kb.cert.org/vuls/id/258564Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.