RULE(RULE ID:805673)

Rule General Information
Release Date: 2019-06-27
Rule Name: FreeBSD NFS Server nfsrvd_readdirplus Denial-of-Service Vulnerability -4 (CVE-2018-17159)
Severity:
CVE ID:
Rule Protection Details
Description: In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks a bounds check in the READDIRPLUS NFS request. Unprivileged remote users with access to the NFS server can cause a resource exhaustion by forcing the server to allocate an arbitrarily large memory allocation.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:106192
SecurityTrackerID:1042164
https://secuniaresearch.flexerasoftware.com/secunia_research/2018-24/
https://security.freebsd.org/advisories/FreeBSD-SA-18:13.nfs.asc
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.freebsd.org/security/advisories/FreeBSD-SA-18:13.nfs.asc