First published: Mon Jun 22 2020(Updated: )
It was discovered that the nfs-utils package set incorrect permissions on the /var/lib/nfs directory. An attacker could possibly use this issue to escalate privileges.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/nfs-common | <1:1.3.4-2.5ubuntu3.3 | 1:1.3.4-2.5ubuntu3.3 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/nfs-common | <1:1.3.4-2.5ubuntu2.1 | 1:1.3.4-2.5ubuntu2.1 |
Ubuntu | =19.10 | |
All of | ||
ubuntu/nfs-common | <1:1.3.4-2.1ubuntu5.3 | 1:1.3.4-2.1ubuntu5.3 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/nfs-common | <1:1.2.8-9ubuntu12.3 | 1:1.2.8-9ubuntu12.3 |
Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-4400-1 is considered a high-severity vulnerability due to potential privilege escalation risks.
To fix USN-4400-1, update the nfs-utils package to the recommended version for your Ubuntu distribution.
USN-4400-1 affects nfs-common versions prior to 1:1.3.4-2.5ubuntu3.3 for Ubuntu 20.04, before 1:1.3.4-2.5ubuntu2.1 for Ubuntu 19.10, and others as specified in the advisory.
The vulnerability in USN-4400-1 involves incorrect permissions on the /var/lib/nfs directory.
Yes, USN-4400-1 can potentially lead to privilege escalation, which may result in unauthorized access to sensitive data.