Description
The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the client, which allows remote attackers to bypass file permissions on NFS filesystems via crafted requests.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2743-1 | kfreebsd-9 security update |
EUVD |
EUVD-2013-4696 | The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the client, which allows remote attackers to bypass file permissions on NFS filesystems via crafted requests. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T16:59:40.746Z
Reserved: 2013-07-16T00:00:00.000Z
Link: CVE-2013-4851
No data.
Status : Modified
Published: 2013-07-29T13:59:56.933
Modified: 2026-04-29T01:13:23.040
Link: CVE-2013-4851
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD