RHSA-2009:1321: Low: nfs-utils security and bug fix update

Published Sep 2, 2009
·
Updated

The nfs-utils package provides a daemon for the kernel NFS server andrelated tools.It was discovered that nfs-utils did not use tcpwrappers correctly.Certain hosts access rules defined in "/etc/hosts.allow" and"/etc/hosts.deny" may not have been honored, possibly allowing remoteattackers to bypass intended access restrictions. (CVE-2008-4552)This updated package also fixes the following bugs: the "LOCKDTCPPORT" and "LOCKDUDPPORT" options in "/etc/sysconfig/nfs" were not honored: the lockd daemon continued to use random ports. With thisupdate, these options are honored. (BZ#434795) it was not possible to mount NFS file systems from a system that has the "/etc/" directory mounted on a read-only file system (this could occuron systems with an NFS-mounted root file system). With this update, it ispossible to mount NFS file systems from a system that has "/etc/" mountedon a read-only file system. (BZ#450646) arguments specified by "STATDARG=" in "/etc/sysconfig/nfs" were removed by the nfslock init script, meaning the arguments specified were neverpassed to rpc.statd. With this update, the nfslock init script no longerremoves these arguments. (BZ#459591) when mounting an NFS file system from a host not specified in the NFS server's "/etc/exports" file, a misleading "unknown host" error was loggedon the server (the hostname lookup did not fail). With this update, aclearer error message is provided for these situations. (BZ#463578) the nhfsstone benchmark utility did not work with NFS version 3 and 4. This update adds support to nhfsstone for NFS version 3 and 4. The newnhfsstone "-2", "-3", and "-4" options are used to select an NFS version(similar to nfsstat(8)). (BZ#465933) the exportfs(8) manual page contained a spelling mistake, "djando", in the EXAMPLES section. (BZ#474848) in some situations the NFS server incorrectly refused mounts to hosts that had a host alias in a NIS netgroup. (BZ#478952) in some situations the NFS client used its cache, rather than using the latest version of a file or directory from a given export. This updateadds a new mount option, "lookupcache=", which allows the NFS client tocontrol how it caches files and directories. Note: The Red Hat EnterpriseLinux 5.4 kernel update (the fourth regular update) must be installed inorder to use the "lookupcache=" option. Also, "lookupcache=" is currentlyonly available for NFS version 3. Support for NFS version 4 may beintroduced in future Red Hat Enterprise Linux 5 updates. Refer to Red HatBugzilla #511312 for further information. (BZ#489335)Users of nfs-utils should upgrade to this updated package, which containsbackported patches to correct these issues. After installing this update,the nfs service will be restarted automatically.

Affected Software

2 affected componentsFixes available
redhat/nfs-utils<1.0.9-42.el5
1.0.9-42.el5
redhat/nfs-utils<1.0.9-42.el5
1.0.9-42.el5

Remediation

Event History

Sep 2, 2009
Advisory Published
via Red Hat·12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2009:1321?

The severity of RHSA-2009:1321 is classified as moderate.

2

How do I fix RHSA-2009:1321?

To fix RHSA-2009:1321, update the nfs-utils package to version 1.0.9-42.el5 or later.

3

What does RHSA-2009:1321 affect?

RHSA-2009:1321 affects the nfs-utils package, specifically its configuration in relation to tcp_wrappers.

4

What are the risks associated with RHSA-2009:1321?

The risks associated with RHSA-2009:1321 include potential unauthorized access due to improper enforcement of access rules.

5

Is there a workaround for RHSA-2009:1321?

There is no specific workaround for RHSA-2009:1321; the only effective solution is to apply the recommended update.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203