nfs-utils vulnerability

Related Vulnerabilities: CVE-2019-3689  

nfs-utils could be made to overwrite files as the administrator.

It was discovered that the nfs-utils package set incorrect permissions on the /var/lib/nfs directory. An attacker could possibly use this issue to escalate privileges.

22 June 2020

nfs-utils vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 20.04 LTS
  • Ubuntu 19.10
  • Ubuntu 18.04 LTS
  • Ubuntu 16.04 LTS

Summary

nfs-utils could be made to overwrite files as the administrator.

Software Description

  • nfs-utils - None

Details

It was discovered that the nfs-utils package set incorrect permissions on the /var/lib/nfs directory. An attacker could possibly use this issue to escalate privileges.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 20.04 LTS
nfs-common - 1:1.3.4-2.5ubuntu3.3
Ubuntu 19.10
nfs-common - 1:1.3.4-2.5ubuntu2.1
Ubuntu 18.04 LTS
nfs-common - 1:1.3.4-2.1ubuntu5.3
Ubuntu 16.04 LTS
nfs-common - 1:1.2.8-9ubuntu12.3

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References