CVE-2008-4552: High severity suse nfs-utils vulnerability
It seems that tcpwrappers does not honor netgroups. As this was noted in a different unrelated bug, I'm opening this one: https://bugzilla.redhat.com/showbug.cgi?id=440114#c8
It seems that netgroups are not working; if I put in my hosts.allow file
mountd: hostname - or - mountd: ip-address
then I can mount, but if I have a netgroup, I can't... for instance
mountd: @selectedhosts
Can you confirm this behaviour?
Other sources
The goodclient function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hostsctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroups and allows remote attackers to bypass intended access restrictions.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4552?
The severity of CVE-2008-4552 is considered medium, as it allows remote attackers to bypass access restrictions.
How do I fix CVE-2008-4552?
To fix CVE-2008-4552, upgrade nfs-utils to version 1.1.3 or later.
What versions of nfs-utils are affected by CVE-2008-4552?
CVE-2008-4552 affects nfs-utils versions up to 1.1.2, including 1.0.9.
Can CVE-2008-4552 be exploited remotely?
Yes, CVE-2008-4552 can be exploited remotely without authentication.
What is the impact of CVE-2008-4552 on system security?
CVE-2008-4552 allows unauthorized access to NFS shared resources, compromising system security.