Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.69603
Category:FreeBSD Local Security Checks
Title:FreeBSD Security Advisory (FreeBSD-SA-11:01.mountd.asc)
Summary:The remote host is missing an update to the system; as announced in the referenced advisory FreeBSD-SA-11:01.mountd.asc
Description:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory FreeBSD-SA-11:01.mountd.asc

Vulnerability Insight:
The mountd(8) daemon services NFS mount requests from other client
machines. When mountd is started, it loads the export host addresses
and options into the kernel using the mount(2) system call.

While parsing the exports(5) table, a network mask in the form of

- network=netname/prefixlength results in an incorrect network mask
being computed if the prefix length is not a multiple of 8.

For example, specifying the ACL for an export as -network 192.0.2.0/23
would result in a netmask of 255.255.127.0 being used instead of the
correct netmask of 255.255.254.0.

Solution:
Upgrade your system to the appropriate stable release
or security branch dated after the correction date.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-1739
BugTraq ID: 47517
http://www.securityfocus.com/bid/47517
FreeBSD Security Advisory: FreeBSD-SA-11:01
http://security.FreeBSD.org/advisories/FreeBSD-SA-11:01.mountd.asc
http://securitytracker.com/id?1025425
http://secunia.com/advisories/44307
http://www.vupen.com/english/advisories/2011/1076
XForce ISS Database: freebsd-mountd-security-bypass(66981)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66981
CopyrightCopyright (C) 2011 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.