Vulnerability Name:

CVE-2013-1923 (CCN-85331)

Assigned:2013-05-09
Published:2013-05-09
Updated:2017-08-29
Summary:rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks.
CVSS v3 Severity:3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:3.2 Low (CVSS v2 Vector: AV:A/AC:H/Au:N/C:P/I:P/A:N)
2.4 Low (Temporal CVSS v2 Vector: AV:A/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Other
References:Source: MITRE
Type: CNA
CVE-2013-1923

Source: CCN
Type: nfs-utils GIT Repository
Avoid DNS reverse resolution for server names (take 3)

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2013:1012

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2013:1016

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2013:1048

Source: MLIST
Type: UNKNOWN
[linux-nfs] 20130402 Re: [PATCH] Avoid PTR lookups when possible

Source: MLIST
Type: UNKNOWN
[linux-nfs] 20130403 Re: [PATCH] Avoid PTR lookups when possible

Source: BID
Type: UNKNOWN
58854

Source: CCN
Type: BID-58854
nfs-utils 'rpc.gssd' DNS Spoofing Vulnerability

Source: CCN
Type: Red Hat Bugzilla Bug 948072
CVE-2013-1923 nfs-utils: rpc.gssd is vulnerable to DNS spoofing

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.redhat.com/show_bug.cgi?id=948072

Source: XF
Type: UNKNOWN
nfsutils-cve20131923-spoofing(85331)

Source: XF
Type: UNKNOWN
nfsutils-cve20131923-spoofing(85331)

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2013-1923

Vulnerable Configuration:Configuration 1:
  • cpe:/a:linux-nfs:nfs-utils:1.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:linux-nfs:nfs-utils:1.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:linux-nfs:nfs-utils:1.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:linux-nfs:nfs-utils:1.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:linux-nfs:nfs-utils:1.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:linux-nfs:nfs-utils:1.2.5:*:*:*:*:*:*:*
  • OR cpe:/a:linux-nfs:nfs-utils:1.2.6:*:*:*:*:*:*:*
  • OR cpe:/a:linux-nfs:nfs-utils:*:*:*:*:*:*:*:* (Version <= 1.2.7)

  • Configuration CCN 1:
  • cpe:/a:nfs:nfs-utils:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:42405
    P
    Security update for curl (Important)
    2022-07-07
    oval:org.opensuse.security:def:20131923
    V
    CVE-2013-1923
    2022-05-20
    oval:org.opensuse.security:def:26226
    P
    Security update for openexr (Important)
    2022-01-12
    oval:org.opensuse.security:def:26225
    P
    Security update for libsndfile (Important)
    2022-01-05
    oval:org.opensuse.security:def:32240
    P
    Security update for the Linux Kernel (Live Patch 41 for SLE 12 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:31717
    P
    Security update for openssh (Important)
    2021-12-06
    oval:org.opensuse.security:def:31716
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:26177
    P
    Security update for webkit2gtk3 (Important)
    2021-12-01
    oval:org.opensuse.security:def:32218
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:26141
    P
    Security update for webkit2gtk3 (Important)
    2021-10-06
    oval:org.opensuse.security:def:31682
    P
    Security update for openssl (Low)
    2021-09-20
    oval:org.opensuse.security:def:26124
    P
    Security update for openssl-1_1 (Low)
    2021-09-09
    oval:org.opensuse.security:def:32179
    P
    Security update for libesmtp (Important)
    2021-09-02
    oval:org.opensuse.security:def:32170
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-08-25
    oval:org.opensuse.security:def:32961
    P
    Security update for kernel-source (Important)
    2021-07-01
    oval:org.opensuse.security:def:32130
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP3) (Important)
    2021-06-18
    oval:org.opensuse.security:def:36250
    P
    nfs-client-1.2.3-18.38.43.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42657
    P
    nfs-client-1.2.3-18.38.43.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32922
    P
    Security update for curl (Moderate)
    2021-05-26
    oval:org.opensuse.security:def:32083
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:32074
    P
    Security update for MozillaFirefox (Important)
    2021-04-27
    oval:org.opensuse.security:def:32284
    P
    Security update for openssl (Moderate)
    2021-03-24
    oval:org.opensuse.security:def:31728
    P
    Security update for jasper (Important)
    2021-02-16
    oval:org.opensuse.security:def:26084
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:25973
    P
    Security update for the Linux Kernel (Important)
    2020-12-09
    oval:org.opensuse.security:def:35998
    P
    nfs-client-1.2.3-18.31.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:32382
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25547
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:27213
    P
    librsvg on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32431
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:25548
    P
    Security update for ceph (Important)
    2020-12-01
    oval:org.opensuse.security:def:27248
    P
    nfs-client on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31774
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31802
    P
    Security update for adns (Important)
    2020-12-01
    oval:org.opensuse.security:def:32470
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:25559
    P
    Security update for mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:25799
    P
    Security update for gcc48 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26376
    P
    Security update for MozillaThunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31831
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:31934
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:32492
    P
    boost-license on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25623
    P
    Security update for cifs-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26265
    P
    Security update for guile (Low)
    2020-12-01
    oval:org.opensuse.security:def:25800
    P
    Security update for polkit (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26429
    P
    Security update for keepalived (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31918
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32026
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32536
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25751
    P
    Security update for libssh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26279
    P
    Security update for gimp (Low)
    2020-12-01
    oval:org.opensuse.security:def:25811
    P
    Security update for libvirt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26478
    P
    Security update for nextcloud (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31464
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33174
    P
    libproxy0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25832
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:26323
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25875
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26517
    P
    NetworkManager-gnome on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31465
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33213
    P
    nfs-client on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25889
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:26961
    P
    libopenssl0_9_8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26003
    P
    Security update for yaml-cpp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26531
    P
    coolkey on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31476
    P
    Security update for puppet
    2020-12-01
    oval:org.opensuse.security:def:32326
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:26996
    P
    nfs-client on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26575
    P
    krb5-doc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31550
    P
    Security update for shim (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:26060
    P
    SUSE-SU-2013:0822-1 -- Security update for nfs-utils
    2014-09-08
    oval:org.mitre.oval:def:26093
    P
    SUSE-SU-2013:0821-1 -- Security update for nfs-client
    2014-09-08
    oval:org.mitre.oval:def:25681
    P
    SUSE-SU-2013:1668-1 -- Security update for nfs-utils
    2014-09-08
    oval:com.ubuntu.artful:def:20131923000
    V
    CVE-2013-1923 on Ubuntu 17.10 (artful) - low.
    2014-01-21
    oval:com.ubuntu.bionic:def:201319230000000
    V
    CVE-2013-1923 on Ubuntu 18.04 LTS (bionic) - low.
    2014-01-21
    oval:com.ubuntu.trusty:def:20131923000
    V
    CVE-2013-1923 on Ubuntu 14.04 LTS (trusty) - low.
    2014-01-21
    oval:com.ubuntu.bionic:def:20131923000
    V
    CVE-2013-1923 on Ubuntu 18.04 LTS (bionic) - low.
    2014-01-21
    oval:com.ubuntu.xenial:def:201319230000000
    V
    CVE-2013-1923 on Ubuntu 16.04 LTS (xenial) - low.
    2014-01-21
    oval:com.ubuntu.xenial:def:20131923000
    V
    CVE-2013-1923 on Ubuntu 16.04 LTS (xenial) - low.
    2014-01-21
    oval:com.ubuntu.cosmic:def:20131923000
    V
    CVE-2013-1923 on Ubuntu 18.10 (cosmic) - low.
    2014-01-21
    oval:com.ubuntu.disco:def:201319230000000
    V
    CVE-2013-1923 on Ubuntu 19.04 (disco) - low.
    2014-01-21
    oval:com.ubuntu.cosmic:def:201319230000000
    V
    CVE-2013-1923 on Ubuntu 18.10 (cosmic) - low.
    2014-01-21
    oval:com.ubuntu.precise:def:20131923000
    V
    CVE-2013-1923 on Ubuntu 12.04 LTS (precise) - low.
    2014-01-21
    BACK
    linux-nfs nfs-utils 1.2.0
    linux-nfs nfs-utils 1.2.1
    linux-nfs nfs-utils 1.2.2
    linux-nfs nfs-utils 1.2.3
    linux-nfs nfs-utils 1.2.4
    linux-nfs nfs-utils 1.2.5
    linux-nfs nfs-utils 1.2.6
    linux-nfs nfs-utils *
    nfs nfs-utils *