3.3
CVSSv2

CVE-2011-1749

Published: 26/02/2014 Updated: 10/03/2014
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils prior to 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.

Vulnerable Product Search on Vulmon Subscribe to Product

linux-nfs nfs-utils

linux-nfs nfs-utils 1.2.0

linux-nfs nfs-utils 1.2.1

linux-nfs nfs-utils 1.2.2

Vendor Advisories

Debian Bug report logs - #629420 CVE-2011-1749: nfs-utils: mountnfs fails to anticipate RLIMIT_FSIZE Package: nfs-utils; Maintainer for nfs-utils is Debian kernel team <debian-kernel@listsdebianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Mon, 6 Jun 2011 15:03:01 UTC Severity: important ...
Synopsis Low: nfs-utils security, bug fix, and enhancement update Type/Severity Security Advisory: Low Topic Updated nfs-utils packages that fix two security issues, various bugs, andadd one enhancement are now available for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update ...
Synopsis Low: nfs-utils security, bug fix, and enhancement update Type/Severity Security Advisory: Low Topic An updated nfs-utils package that fixes one security issue, various bugs,and adds one enhancement is now available for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this upd ...