Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2011-1534

Опубликовано: 14 дек. 2011
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2011-1534: nfs-utils security, bug fix, and enhancement update (LOW)

[1.2.3-15]

  • mout.nfs: Don't roll back to IPv4 whe IPv6 fails (bz 744657)
  • rpcdebug: Added pNFS and FSCache debugging (bz 747400)

[1.2.3-14]

  • mount.nfs: Backported how upstream handles the SIGXFSZ signal (bz 697981)

[1.2.3-13]

  • mount.nfs: Reworked the code that deals with RLIMIT_FSIZE (bz 697981)

[1.2.3-12]

  • Removed the stripping of debugging information from rpcdebug (bz 729001)

[1.2.3-11]

  • mount.nfs: Fixed problem in mount error verbosity patch (bz 731693)

[1.2.3-10]

  • mount.nfs: add error verbosity to invalid versions (bz 731693)

[1.2.3-9]

  • umount.nfs: Got IPV6 unmounts working again (bz 732673)
  • mountd: return multiple hosts exporting the same directory (bz 726112)
  • mount: Better error message for invalid version (bz 723780)

[1.2.3-8]

  • initscripts: just try to mount rpc_pipefs always (bz 692702)
  • Rely on crypto module autoloading in init scripts
  • svcgssd: Document '-n' for svcgssd (bz 697359)
  • mount.nfs: anticipate RLIMIT_FSIZE (bz 697981)
  • exportfs manpage: Ipv6 update (bz 715078)
  • mountd: Stop segfault in mtab code (bz 723438)
  • exportfs: wilcards in exports can lead to unintended mounts (bz 715391)
  • umount: allow spaces in unmount paths (bz 702273)
  • specfile: reordered how libgssglue is linked in (bz 720479)

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

nfs-utils

1.2.3-15.el6

Oracle Linux i686

nfs-utils

1.2.3-15.el6

Связанные CVE

Связанные уязвимости

ubuntu
больше 11 лет назад

The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.

redhat
около 14 лет назад

The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.

nvd
больше 11 лет назад

The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.

debian
больше 11 лет назад

The host_reliable_addrinfo function in support/export/hostname.c in nf ...

ubuntu
больше 11 лет назад

The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.