CVE-2004-0154: Medium severity nfs nfs-utils vulnerability
Published May 12, 2004
·Updated
rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.
Affected Software
5 affected components
nfs nfs-utils=1.0
nfs nfs-utils=1.0.1
nfs nfs-utils=1.0.3
nfs nfs-utils=1.0.4
nfs nfs-utils=1.0.6
Remediation
Patch Available
Patch Available
Event History
May 12, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0154?
CVE-2004-0154 has a severity rating that indicates it can lead to a denial of service within affected versions of nfs-utils.
2
How do I fix CVE-2004-0154?
To resolve CVE-2004-0154, you should upgrade nfs-utils to a version that is not affected, specifically version 1.0.6 or later.
3
What versions of nfs-utils are affected by CVE-2004-0154?
CVE-2004-0154 affects nfs-utils versions 1.0.3, 1.0.4, and 1.0.5.
4
Can CVE-2004-0154 be exploited remotely?
Yes, CVE-2004-0154 can be exploited remotely through an NFS mount from a malicious client.
5
What kind of attack does CVE-2004-0154 enable?
CVE-2004-0154 enables an attacker to cause a denial of service by crashing the rpc.mountd service.