7.5
CVSSv2

CVE-2013-3266

Published: 02/05/2013 Updated: 25/11/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The nfsrvd_readdir function in sys/fs/nfsserver/nfs_nfsdport.c in the new NFS server in FreeBSD 8.0 up to and including 9.1-RELEASE-p3 does not verify that a READDIR request is for a directory node, which allows remote malicious users to cause a denial of service (memory corruption) or possibly execute arbitrary code by specifying a plain file instead of a directory.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 8.2

freebsd freebsd 9.0

freebsd freebsd 8.3

freebsd freebsd 8.0

freebsd freebsd 8.1

freebsd freebsd 9.1

Vendor Advisories

Adam Nowacki discovered that the new FreeBSD NFS implementation processes a crafted READDIR request which instructs to operate a file system on a file node as if it were a directory node, leading to a kernel crash or potentially arbitrary code execution The kfreebsd-8 kernel in the oldstable distribution (squeeze) does not enable the new NFS imple ...