RHSA-2007:0913: Important: nfs-utils-lib security update
The nfs-utils-lib package contains support libraries that are needed by thecommands and daemons of the nfs-utils package.Tenable Network Security discovered a stack buffer overflow flaw in the RPClibrary used by nfs-utils-lib. A remote unauthenticated attacker who canaccess an application linked against nfs-utils-lib could trigger this flawand cause the application to crash. On Red Hat Enterprise Linux 4 it is notpossible to exploit this flaw to run arbitrary code as the overflow isblocked by FORTIFYSOURCE. (CVE-2007-3999)Users of nfs-utils-lib are advised to upgrade to this updated package,which contains a backported patch that resolves this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2007:0913?
The severity of RHSA-2007:0913 is classified as important.
How do I fix RHSA-2007:0913?
To fix RHSA-2007:0913, update the nfs-utils-lib package to the latest version provided by Red Hat.
What systems are affected by RHSA-2007:0913?
RHSA-2007:0913 affects systems that use the nfs-utils-lib package.
What type of vulnerability is associated with RHSA-2007:0913?
RHSA-2007:0913 is associated with a stack buffer overflow vulnerability in the RPC library.
Can an attacker exploit RHSA-2007:0913 remotely?
Yes, a remote unauthenticated attacker can exploit RHSA-2007:0913 if they gain access to an affected system.