3.2
CVSSv2

CVE-2013-1923

Published: 21/01/2014 Updated: 29/08/2017
CVSS v2 Base Score: 3.2 | Impact Score: 4.9 | Exploitability Score: 3.2
VMScore: 285
Vector: AV:A/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

rpc-gssd in nfs-utils prior to 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote malicious users to read otherwise-restricted files via DNS spoofing attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux-nfs nfs-utils 1.2.2

linux-nfs nfs-utils 1.2.1

linux-nfs nfs-utils

linux-nfs nfs-utils 1.2.6

linux-nfs nfs-utils 1.2.5

linux-nfs nfs-utils 1.2.4

linux-nfs nfs-utils 1.2.3

linux-nfs nfs-utils 1.2.0

Vendor Advisories

Debian Bug report logs - #707401 nfs-utils: CVE-2013-1923: rpcgssd is vulnerable to DNS spoofing Package: nfs-utils; Maintainer for nfs-utils is Debian kernel team <debian-kernel@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 9 May 2013 08:16:12 UTC Severity: important Tags: sec ...
rpc-gssd in nfs-utils before 128 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks ...