CVE-2011-2500: High severity nfs-utils vulnerability
A security flaw was found in the way nfs-utils performed authentication of an incoming request, when an IP based authentication mechanism was used and certain file systems were exported to either to a netgroup or a wildcard (e.g. .my.domain), and some file systems (either the same or different to the first set) were exported to specific hosts, IP addresses, or a subnet. A remote attacker, able to create global DNS entries could use this flaw to access above listed, exported file systems.
References: [1] https://bugzilla.novell.com/showbug.cgi?id=701702 [2] http://www.openwall.com/lists/oss-security/2011/06/27/7 (CVE Request)
Relevant upstream patch: [3] http://marc.info/?l=linux-nfs&m=130875695821953&w=2
Other sources
The hostreliableaddrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2500?
CVE-2011-2500 is considered a moderate severity vulnerability due to its potential impact on authentication mechanisms.
How do I fix CVE-2011-2500?
To fix CVE-2011-2500, upgrade the nfs-utils package to version 1:1.2.3-15.el6 or higher.
What types of systems are affected by CVE-2011-2500?
CVE-2011-2500 affects systems using nfs-utils with IP based authentication and certain exported file systems.
Can CVE-2011-2500 be exploited remotely?
Yes, CVE-2011-2500 can be exploited remotely if vulnerable systems are configured with improper authentication settings.
Which versions of nfs-utils are vulnerable to CVE-2011-2500?
nfs-utils versions prior to 1:1.2.3-15.el6, including 1.2.0 through 1.2.2, are vulnerable to CVE-2011-2500.