Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.69603
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Security Advisory (FreeBSD-SA-11:01.mountd.asc)
Resumen:The remote host is missing an update to the system; as announced in the referenced advisory FreeBSD-SA-11:01.mountd.asc
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory FreeBSD-SA-11:01.mountd.asc

Vulnerability Insight:
The mountd(8) daemon services NFS mount requests from other client
machines. When mountd is started, it loads the export host addresses
and options into the kernel using the mount(2) system call.

While parsing the exports(5) table, a network mask in the form of

- network=netname/prefixlength results in an incorrect network mask
being computed if the prefix length is not a multiple of 8.

For example, specifying the ACL for an export as -network 192.0.2.0/23
would result in a netmask of 255.255.127.0 being used instead of the
correct netmask of 255.255.254.0.

Solution:
Upgrade your system to the appropriate stable release
or security branch dated after the correction date.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-1739
BugTraq ID: 47517
http://www.securityfocus.com/bid/47517
FreeBSD Security Advisory: FreeBSD-SA-11:01
http://security.FreeBSD.org/advisories/FreeBSD-SA-11:01.mountd.asc
http://securitytracker.com/id?1025425
http://secunia.com/advisories/44307
http://www.vupen.com/english/advisories/2011/1076
XForce ISS Database: freebsd-mountd-security-bypass(66981)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66981
CopyrightCopyright (C) 2011 E-Soft Inc.

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.