Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.63647
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDVSA-2009:060-1 (nfs-utils)
Summary:The remote host is missing an update to nfs-utils;announced via advisory MDVSA-2009:060-1.
Description:Summary:
The remote host is missing an update to nfs-utils
announced via advisory MDVSA-2009:060-1.

Vulnerability Insight:
A security vulnerability has been identified and fixed in nfs-utils,
which caused TCP Wrappers to ignore netgroups and allows remote
attackers to bypass intended access restrictions (CVE-2008-4552).

The updated packages have been patched to prevent this.

Update:

The Corporate Server 4 packages had the wrong release number (lower
than before) which prevented the update packages from being installed
automatically. This problem has now been solved with new packages
with the correct release number.

Affected: Corporate 4.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-4552
20081030 rPSA-2008-0307-1 nfs-client nfs-server nfs-utils
http://www.securityfocus.com/archive/1/497935/100/0/threaded
31823
http://www.securityfocus.com/bid/31823
32346
http://secunia.com/advisories/32346
32481
http://secunia.com/advisories/32481
33006
http://secunia.com/advisories/33006
36538
http://secunia.com/advisories/36538
38794
http://secunia.com/advisories/38794
38833
http://secunia.com/advisories/38833
ADV-2010-0528
http://www.vupen.com/english/advisories/2010/0528
MDVSA-2009:060
http://www.mandriva.com/security/advisories?name=MDVSA-2009:060
RHSA-2009:1321
http://www.redhat.com/support/errata/RHSA-2009-1321.html
USN-687-1
http://www.ubuntu.com/usn/USN-687-1
[oss-security] 20120719 CVE Request: quota: incorrect use of tcp_wrappers
http://www.openwall.com/lists/oss-security/2012/07/19/2
[oss-security] 20120719 Re: CVE Request: quota: incorrect use of tcp_wrappers
http://www.openwall.com/lists/oss-security/2012/07/19/5
[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates
http://lists.vmware.com/pipermail/security-announce/2010/000082.html
http://wiki.rpath.com/Advisories:rPSA-2008-0307
https://bugzilla.redhat.com/show_bug.cgi?id=458676
nfsutils-hostctl-security-bypass(45895)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45895
oval:org.mitre.oval:def:11544
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11544
oval:org.mitre.oval:def:8325
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8325
CopyrightCopyright (C) 2009 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.