
CVE-2019-3689 – nfs-utils: root-owned files stored in insecure /var/lib/nfs directory
https://notcve.org/view.php?id=CVE-2019-3689
19 Sep 2019 — The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system. El paquete nfs-utils en SUSE Linux Enterprise Server 12 en versiones anterior... • http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00071.html • CWE-276: Incorrect Default Permissions •

CVE-2013-1923 – Mandriva Linux Security Advisory 2013-178
https://notcve.org/view.php?id=CVE-2013-1923
25 Jun 2013 — rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks. rpc-gssd en nfs-utils anterior a la versión 1.2.8 realiza resoluciones inversas de DNS en nombres de servidor durante la autenticación GSSAPI, lo que podría permitir a atacantes remotos leer archivos restringidos del mismo modo a través de ataques de falsificación de DNS. Updated nfs-utils packages fi... • http://lists.opensuse.org/opensuse-updates/2013-06/msg00142.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •