|
|||
Rule General Information |
---|
Release Date: | 2019-04-02 | |
Rule Name: | FreeBSD NFS Server NFSv4 Opcode Out-of-Bounds Write Vulnerability -1 (CVE-2018-17157) | |
Severity: | ||
CVE ID: | ||
CNNVD ID: | ||
Rule Protection Details |
---|
Description: | In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 request. Unprivileged remote users with access to the NFS server may be able to execute arbitrary code. | |
Impact: | A remote attacker could exploit this vulnerability by sending a crafted NFSv4 (RPC) packet to a vulnerable server. Successful exploitation of this vulnerability could cause denial-of-service conditions or, in the worst case, arbitrary code execution. | |
Affected OS: | Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others | |
Reference: | SecurityFocusBID:106192 SecurityTrackerID:1042164 https://secuniaresearch.flexerasoftware.com/secunia_research/2018-25/ https://security.freebsd.org/advisories/FreeBSD-SA-18:13.nfs.asc |
|
Solutions |
---|
Upgrading to version 11.2-STABLE(r340854) or 11.2-RELEASE-p5 eliminates this vulnerability. |