Oval Definition:oval:com.redhat.rhsa:def:20040072
Revision Date:2004-03-11Version:502
Title:RHSA-2004:072: nfs-utils security update (Low)
Description:The nfs-utils package contains the rpc.mountd program, which implements the NFS mount protocol.

A flaw was discovered in versions of rpc.mountd in nfs-utils versions after 1.0.3 and prior to 1.0.6. When mounting a directory, rpc.mountd could crash if the reverse lookup of the client in DNS failed to match the forward lookup. An attacker who has the ability to mount remote directories from a server could make use of this flaw to cause a denial of service by making rpc.mountd crash.

Users are advised to upgrade to these updated packages, which contain nfs-utils 1.0.6 and is not vulnerable to this issue.

NOTE: Red Hat Enterprise Linux 2.1 includes a version of rpc.mountd that is not vulnerable to this issue.
Family:unixClass:patch
Status:Reference(s):CVE-2004-0154
RHSA-2004:072-01
Platform(s):Red Hat Enterprise Linux 3
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 3 is installed
  • AND nfs-utils is earlier than 0:1.0.6-7.EL
  • AND nfs-utils is signed with Red Hat master key
  • BACK