Описание
ELSA-2011-1534: nfs-utils security, bug fix, and enhancement update (LOW)
[1.2.3-15]
- mout.nfs: Don't roll back to IPv4 whe IPv6 fails (bz 744657)
- rpcdebug: Added pNFS and FSCache debugging (bz 747400)
[1.2.3-14]
- mount.nfs: Backported how upstream handles the SIGXFSZ signal (bz 697981)
[1.2.3-13]
- mount.nfs: Reworked the code that deals with RLIMIT_FSIZE (bz 697981)
[1.2.3-12]
- Removed the stripping of debugging information from rpcdebug (bz 729001)
[1.2.3-11]
- mount.nfs: Fixed problem in mount error verbosity patch (bz 731693)
[1.2.3-10]
- mount.nfs: add error verbosity to invalid versions (bz 731693)
[1.2.3-9]
- umount.nfs: Got IPV6 unmounts working again (bz 732673)
- mountd: return multiple hosts exporting the same directory (bz 726112)
- mount: Better error message for invalid version (bz 723780)
[1.2.3-8]
- initscripts: just try to mount rpc_pipefs always (bz 692702)
- Rely on crypto module autoloading in init scripts
- svcgssd: Document '-n' for svcgssd (bz 697359)
- mount.nfs: anticipate RLIMIT_FSIZE (bz 697981)
- exportfs manpage: Ipv6 update (bz 715078)
- mountd: Stop segfault in mtab code (bz 723438)
- exportfs: wilcards in exports can lead to unintended mounts (bz 715391)
- umount: allow spaces in unmount paths (bz 702273)
- specfile: reordered how libgssglue is linked in (bz 720479)
Обновленные пакеты
Oracle Linux 6
Oracle Linux x86_64
nfs-utils
1.2.3-15.el6
Oracle Linux i686
nfs-utils
1.2.3-15.el6
Связанные CVE
Связанные уязвимости
The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.
The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.
The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.
The host_reliable_addrinfo function in support/export/hostname.c in nf ...
The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.