CVE-2008-4552
The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroups and allows remote attackers to bypass intended access…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroups and allows remote attackers to bypass intended access restrictions.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.30% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- nfs/nfs-utils
- Source
- secalert@redhat.com
References
- http://lists.vmware.com/pipermail/security-announce/2010/000082.html
- http://secunia.com/advisories/32346Vendor Advisory
- http://secunia.com/advisories/32481Vendor Advisory
- http://secunia.com/advisories/33006Vendor Advisory
- http://secunia.com/advisories/36538
- http://secunia.com/advisories/38794Vendor Advisory
- http://secunia.com/advisories/38833Vendor Advisory
- http://wiki.rpath.com/Advisories:rPSA-2008-0307
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:060
- http://www.openwall.com/lists/oss-security/2012/07/19/2
- http://www.openwall.com/lists/oss-security/2012/07/19/5
- http://www.redhat.com/support/errata/RHSA-2009-1321.html
- http://www.securityfocus.com/archive/1/497935/100/0/threaded
- http://www.securityfocus.com/bid/31823Patch
- http://www.ubuntu.com/usn/USN-687-1
- http://www.vupen.com/english/advisories/2010/0528Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=458676
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45895
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11544
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8325
- http://lists.vmware.com/pipermail/security-announce/2010/000082.html
- http://secunia.com/advisories/32346Vendor Advisory
- http://secunia.com/advisories/32481Vendor Advisory
- http://secunia.com/advisories/33006Vendor Advisory
- http://secunia.com/advisories/36538
- http://secunia.com/advisories/38794Vendor Advisory
- http://secunia.com/advisories/38833Vendor Advisory
- http://wiki.rpath.com/Advisories:rPSA-2008-0307
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:060
- http://www.openwall.com/lists/oss-security/2012/07/19/2
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.