REDHAT-BUG-716949: Low severity suse nfs-utils vulnerability
A security flaw was found in the way nfs-utils performed authentication of an incoming request, when an IP based authentication mechanism was used and certain file systems were exported to either to a netgroup or a wildcard (e.g. .my.domain), and some file systems (either the same or different to the first set) were exported to specific hosts, IP addresses, or a subnet. A remote attacker, able to create global DNS entries could use this flaw to access above listed, exported file systems.
References: [1] https://bugzilla.novell.com/showbug.cgi?id=701702 [2] http://www.openwall.com/lists/oss-security/2011/06/27/7 (CVE Request)
Relevant upstream patch: [3] http://marc.info/?l=linux-nfs&m=130875695821953&w=2
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-716949?
The severity of REDHAT-BUG-716949 is classified as high due to the potential for unauthorized access to exported file systems.
How do I fix REDHAT-BUG-716949?
To fix REDHAT-BUG-716949, update nfs-utils to the latest version that addresses this vulnerability.
What systems are affected by REDHAT-BUG-716949?
REDHAT-BUG-716949 affects systems using nfs-utils with IP-based authentication mechanisms and certain file systems exported to netgroups or wildcards.
What impact does REDHAT-BUG-716949 have on network file sharing?
REDHAT-BUG-716949 can lead to potential unauthorized access or data exposure in network file sharing scenarios.
Is there a workaround for REDHAT-BUG-716949 until I can apply a patch?
A possible workaround for REDHAT-BUG-716949 includes modifying export options to avoid using wildcard entries until a patch is applied.