2 results (0.003 seconds)

CVSS: 10.0EPSS: 1%CPEs: 4EXPL: 0

The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system. El paquete nfs-utils en SUSE Linux Enterprise Server 12 en versiones anteriores e incluyendo la versión 1.3.0-34.18.1 y en SUSE Linux Enterprise Server 15 en versiones anteriores e incluyendo la versión 2.1.1-6.10.2, el directorio /var/lib/nfs es propiedad de statd:nogroup. Este directorio contiene archivos de propiedad y administrados por root. • http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00071.html http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00006.html https://bugzilla.suse.com/show_bug.cgi?id=1150733 https://git.linux-nfs.org/?p=steved/nfs-utils.git%3Ba=commitdiff%3Bh=fee2cc29e888f2ced6a76990923aef19d326dc0e https://lists.debian.org/debian-lts-announce/2019/10/msg00026.html https://usn.ubuntu.com/4400-1 • CWE-276: Incorrect Default Permissions •

CVSS: 3.2EPSS: 0%CPEs: 8EXPL: 0

rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks. rpc-gssd en nfs-utils anterior a la versión 1.2.8 realiza resoluciones inversas de DNS en nombres de servidor durante la autenticación GSSAPI, lo que podría permitir a atacantes remotos leer archivos restringidos del mismo modo a través de ataques de falsificación de DNS. • http://lists.opensuse.org/opensuse-updates/2013-06/msg00142.html http://lists.opensuse.org/opensuse-updates/2013-06/msg00146.html http://lists.opensuse.org/opensuse-updates/2013-06/msg00172.html http://marc.info/?l=linux-nfs&m=136491998607561&w=2 http://marc.info/?l=linux-nfs&m=136500502805121&w=2 http://www.securityfocus.com/bid/58854 https://bugzilla.redhat.com/show_bug.cgi?id=948072 https://exchange.xforce.ibmcloud.com/vulnerabilities/85331 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •