First published: Wed May 12 2004(Updated: )
rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE NFS-utils | =1.0 | |
SUSE NFS-utils | =1.0.1 | |
SUSE NFS-utils | =1.0.3 | |
SUSE NFS-utils | =1.0.4 | |
SUSE NFS-utils | =1.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0154 has a severity rating that indicates it can lead to a denial of service within affected versions of nfs-utils.
To resolve CVE-2004-0154, you should upgrade nfs-utils to a version that is not affected, specifically version 1.0.6 or later.
CVE-2004-0154 affects nfs-utils versions 1.0.3, 1.0.4, and 1.0.5.
Yes, CVE-2004-0154 can be exploited remotely through an NFS mount from a malicious client.
CVE-2004-0154 enables an attacker to cause a denial of service by crashing the rpc.mountd service.