Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vvfw-vgqq-f739

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the client, which allows remote attackers to bypass file permissions on NFS filesystems via crafted requests.

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the client, which allows remote attackers to bypass file permissions on NFS filesystems via crafted requests.

EPSS

Процентиль: 43%
0.00207
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the client, which allows remote attackers to bypass file permissions on NFS filesystems via crafted requests.

nvd
больше 12 лет назад

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the client, which allows remote attackers to bypass file permissions on NFS filesystems via crafted requests.

debian
больше 12 лет назад

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS ser ...

EPSS

Процентиль: 43%
0.00207
Низкий