RULE(RULE ID:712770)

Rule General Information
Release Date: 2019-04-02
Rule Name: FreeBSD NFS Server NFSv4 Opcode Out-of-Bounds Write Vulnerability -1 (CVE-2018-17157)
Severity:
CVE ID:
CNNVD ID:
Rule Protection Details
Description: In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 request. Unprivileged remote users with access to the NFS server may be able to execute arbitrary code.
Impact: A remote attacker could exploit this vulnerability by sending a crafted NFSv4 (RPC) packet to a vulnerable server. Successful exploitation of this vulnerability could cause denial-of-service conditions or, in the worst case, arbitrary code execution.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:106192
SecurityTrackerID:1042164
https://secuniaresearch.flexerasoftware.com/secunia_research/2018-25/
https://security.freebsd.org/advisories/FreeBSD-SA-18:13.nfs.asc
Solutions
Upgrading to version 11.2-STABLE(r340854) or 11.2-RELEASE-p5 eliminates this vulnerability.