Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-4851

Опубликовано: 29 июл. 2013
Источник: nvd
CVSS2: 6.4
EPSS Низкий

Описание

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the client, which allows remote attackers to bypass file permissions on NFS filesystems via crafted requests.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:freebsd:freebsd:8.3:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:9.0:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:9.1:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:9.1:p4:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:9.1:p5:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.02137
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
около 13 лет назад

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the client, which allows remote attackers to bypass file permissions on NFS filesystems via crafted requests.

debian
около 13 лет назад

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS ser ...

github
больше 4 лет назад

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the client, which allows remote attackers to bypass file permissions on NFS filesystems via crafted requests.

EPSS

Процентиль: 80%
0.02137
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-264