CVE-2011-3977: High severity nomachine vulnerability
Published Oct 4, 2011
·Updated
Unspecified vulnerability in nxconfigure.sh in NoMachine NX Node 3.x before 3.5.0-4 and NX Server 3.x before 3.5.0-5 allows local users to read arbitrary files via unknown vectors.
Affected Software
6 affected components
NoMachine NX Node=3.0.0
NoMachine NX Node=3.4.0
NoMachine NX Node=3.5.0
NoMachine NX Server=3.0.0
NoMachine NX Server=3.4.0
NoMachine NX Server=3.5.0
Event History
Oct 4, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3977?
CVE-2011-3977 is categorized as a local vulnerability that can potentially allow unauthorized file access.
2
How do I fix CVE-2011-3977?
To mitigate CVE-2011-3977, you should upgrade NoMachine NX Server and Node to versions 3.5.0-4 or later.
3
Who is affected by CVE-2011-3977?
CVE-2011-3977 affects local users of NoMachine NX Node and Server versions before 3.5.0-4 and 3.5.0-5 respectively.
4
What types of systems are impacted by CVE-2011-3977?
Systems running NoMachine NX Server and Node versions 3.0.0, 3.4.0, or 3.5.0 prior to the updates are impacted by CVE-2011-3977.
5
What are the potential consequences of CVE-2011-3977?
Exploitation of CVE-2011-3977 could allow local users to read sensitive files without proper authorization.