CVE-2010-2020
FreeBSD - 'mountnfs()' Denial of Service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
-Decision
Descriptions
sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount request.
sys/nfsclient/nfs_vfsops.c en el cliente NFS en el kernel en FreeBSD v7.2 hasta v8.1-PRERELEASE, cuando vfs.usermount está habilitado no valida la longitud de ciertos parámetros fhsize, lo que permite a usuarios locales obtener privilegios a través de una petición mount manipulada.
Census Labs have discovered two improper input validation vulnerabilities in the FreeBSD kernel's NFS client-side implementation (FreeBSD 8.0-RELEASE, 7.3-RELEASE and 7.2-RELEASE) that allow local unprivileged users to escalate their privileges, or to crash the system by performing a denial of service attack.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-05-24 CVE Reserved
- 2010-05-28 CVE Published
- 2010-05-28 First Exploit
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1024039 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/90052 | 2010-05-28 | |
https://www.exploit-db.com/exploits/14003 | 2010-06-24 | |
https://www.exploit-db.com/exploits/14002 | 2017-11-16 | |
http://www.exploit-db.com/exploits/14002 | 2024-08-07 | |
http://www.exploit-db.com/exploits/14003 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://security.FreeBSD.org/advisories/FreeBSD-SA-10:06.nfsclient.asc | 2012-11-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | 7.2 Search vendor "Freebsd" for product "Freebsd" and version "7.2" | - |
Affected
| ||||||
Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | 7.2 Search vendor "Freebsd" for product "Freebsd" and version "7.2" | pre-release |
Affected
| ||||||
Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | 7.2 Search vendor "Freebsd" for product "Freebsd" and version "7.2" | stable |
Affected
| ||||||
Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | 8.0 Search vendor "Freebsd" for product "Freebsd" and version "8.0" | - |
Affected
| ||||||
Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | 8.1-prerelease Search vendor "Freebsd" for product "Freebsd" and version "8.1-prerelease" | - |
Affected
|