Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-0946

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2004-0946
Last Modified 21 Aug 2010 12:21:31
Published 10 Jan 2005 12:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2004-0946

Summary

rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attackers to execute arbitrary code via a crafted NFS request.

Vulnerable Systems

Operating System

  • Redhat Enterprise Linux 3.0

  • Redhat Enterprise Linux Desktop 3.0

Application

  • Nfs-utils 1.0

  • Nfs-utils 1.0.1

  • Nfs-utils 1.0.2

  • Nfs-utils 1.0.3

  • Nfs-utils 1.0.4

  • Nfs-utils 1.0.6


References

CERT-VN - VU#698302

BID - 11911

REDHAT - RHSA-2004:583

GENTOO - GLSA-200412-08

XF - nfsutils-getquotainfo-bo(18455)

REDHAT - RHSA-2005:014

SECUNIA - 13440

MISC - http://bugs.gentoo.org/show_bug.cgi?id=72113

FEDORA - FLSA-2006:138098

MANDRAKE - MDKSA-2005:005


Last Updated: 27 May 2016 10:38:49