7.5
CVSSv2

CVE-2008-4552

Published: 14/10/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The good_client function in nfs-utils 1.0.9, and possibly other versions prior to 1.1.3, invokes the hosts_ctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroups and allows remote malicious users to bypass intended access restrictions.

Vulnerable Product Search on Vulmon Subscribe to Product

nfs nfs-utils 0.3.1

nfs nfs-utils 0.2.1

nfs nfs-utils 1.0.3

nfs nfs-utils 1.0.6

nfs nfs-utils 1.0.8

nfs nfs-utils

nfs nfs-utils 0.2

nfs nfs-utils 1.0.2

nfs nfs-utils 1.0.7

nfs nfs-utils 1.0.11

nfs nfs-utils 1.0.12

nfs nfs-utils 1.0

nfs nfs-utils 0.3.3

nfs nfs-utils 1.0.9

nfs nfs-utils 1.0.10

nfs nfs-utils 1.0.1

nfs nfs-utils 1.0.4

nfs nfs-utils 1.1.0

nfs nfs-utils 1.1.1

Vendor Advisories

It was discovered that nfs-utils did not properly enforce netgroup restrictions when using TCP Wrappers Remote attackers could bypass the netgroup restrictions enabled by the administrator and possibly gain access to sensitive information ...