6.4
CVSSv2

CVE-2013-4851

Published: 29/07/2013 Updated: 18/03/2019
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x up to and including 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the client, which allows remote malicious users to bypass file permissions on NFS filesystems via crafted requests.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 9.0

freebsd freebsd 9.1

freebsd freebsd 8.3

Vendor Advisories

Debian Bug report logs - #720468 kfreebsd-9: CVE-2013-3077: local ip_multicast buffer overflow Package: src:kfreebsd-9; Maintainer for src:kfreebsd-9 is (unknown); Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Thu, 22 Aug 2013 11:45:02 UTC Severity: grave Tags: security, upstream Found in versions kfreebsd-9/ ...
Debian Bug report logs - #720475 kfreebsd-9: CVE-2013-5209: sctp kernel memory disclosure Package: src:kfreebsd-9; Maintainer for src:kfreebsd-9 is (unknown); Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Thu, 22 Aug 2013 12:03:06 UTC Severity: grave Tags: security, upstream Found in versions kfreebsd-9/90-1 ...
Several vulnerabilities have been discovered in the FreeBSD kernel that may lead to a privilege escalation or information leak The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-3077 Clement Lecigne from the Google Security Team reported an integer overflow in computing the size of a temporary buf ...