CVE-2009-0180: High severity nfs nfs-utils vulnerability
Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions, possibly a related issue to CVE-2008-1376.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nfs-utils (Fedora 9)to a version that resolves this vulnerability.Fixed in 1.1.2-9.fc9 - Upgrade
Upgrade
nfs-utils (Fedora 10)to a version that resolves this vulnerability.Fixed in 1.1.4-6.fc10
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0180?
CVE-2009-0180 has a medium severity rating due to its potential for remote attackers to bypass access restrictions.
How do I fix CVE-2009-0180?
To fix CVE-2009-0180, update nfs-utils to version 1.1.2-9.fc9 or later on Fedora 9 and version 1.1.4-6.fc10 or later on Fedora 10.
Who is affected by CVE-2009-0180?
CVE-2009-0180 affects users of nfs-utils prior to versions 1.1.2-9.fc9 and 1.1.4-6.fc10 on Fedora systems.
What are the potential impacts of CVE-2009-0180?
The potential impact of CVE-2009-0180 includes unauthorized remote access, leading to possible data breaches.
Is there a workaround for CVE-2009-0180?
A workaround for CVE-2009-0180 is to disable NFS services if immediate patching is not possible.