CVE-2004-1014: Medium severity nfs nfs-utils vulnerability
statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1014?
CVE-2004-1014 is classified as a denial-of-service vulnerability due to the potential for remote attackers to crash the server process.
How do I fix CVE-2004-1014?
To resolve CVE-2004-1014, upgrade to a version of nfs-utils later than 1.257 that properly handles the SIGPIPE signal.
Which software versions are affected by CVE-2004-1014?
CVE-2004-1014 affects nfs-utils versions 1.257 and earlier, as well as specific versions of Red Hat, Debian, and Mandrake Linux.
Can CVE-2004-1014 lead to data loss?
While CVE-2004-1014 primarily causes denial of service, repeated crashes might lead to temporary interruptions that could affect data accessibility.
Is CVE-2004-1014 a critical vulnerability?
CVE-2004-1014 is not considered a critical vulnerability, but it still poses a significant risk of service disruption.