Vulnerability Name: | CVE-2004-0946 (CCN-18455) | ||||||||||||
Assigned: | 2004-11-22 | ||||||||||||
Published: | 2004-11-22 | ||||||||||||
Updated: | 2018-10-19 | ||||||||||||
Summary: | rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attackers to execute arbitrary code via a crafted NFS request. | ||||||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: CCN Type: Bugzilla Bug 72113 net-fs/nfs-utils: buffer overflow on 64bit arches and remote DoS Source: MISC Type: UNKNOWN http://bugs.gentoo.org/show_bug.cgi?id=72113 Source: MITRE Type: CNA CVE-2004-0946 Source: CCN Type: RHSA-2004-583 nfs-utils security update Source: CCN Type: RHSA-2005-014 nfs-utils security update Source: CCN Type: SA13440 nfs-utils "getquotainfo()" Buffer Overflow Vulnerability Source: SECUNIA Type: UNKNOWN 13440 Source: CCN Type: CIAC Information Bulletin P-076 "nfs-utils" Package Vulnerabilities Source: CCN Type: GLSA-200412-08 nfs-utils: Multiple remote vulnerabilities Source: GENTOO Type: Patch, Vendor Advisory GLSA-200412-08 Source: CCN Type: US-CERT VU#698302 nfs-utils vulnerable to buffer overflow in getquotainfo() in rquota_server.c Source: CERT-VN Type: US Government Resource VU#698302 Source: MANDRAKE Type: UNKNOWN MDKSA-2005:005 Source: REDHAT Type: Patch, Vendor Advisory RHSA-2004:583 Source: REDHAT Type: UNKNOWN RHSA-2005:014 Source: FEDORA Type: UNKNOWN FLSA-2006:138098 Source: BID Type: Patch, Vendor Advisory 11911 Source: CCN Type: BID-11911 Linux NFS 64-Bit Architecture Remote Buffer Overflow Vulnerability Source: CCN Type: TLSA-2005-33 NFS denial of service attack Source: XF Type: UNKNOWN nfsutils-getquotainfo-bo(18455) Source: XF Type: UNKNOWN nfsutils-getquotainfo-bo(18455) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10464 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |