Title: Multiple Vendor rpc.mountd File Disclosure Vulnerablity
Severity: HIGH
Description:
rpc.mountd is an RPC server that handles NFS file system mount requests. A vulnerability has been discovered with mountd which, if exploited, allows the attacker to obtain information about any file that exists on the NFS server. This is possible for files that are not a part of the NFS exported file system.
When a request is sent by a client for a file that the client cannot access (not exported to the client), vulnerable versions of this daemon will output a response indicating that permission to access the file is denied. This is a different response than is sent when the file does not exist. From this information an attacker can infer whether a file exists or not without any credentials on the remote server.
Multiple operating systems are affected, including versions of Solaris and HP-UX. This vulnerability may be exploited by attackers to gather information about a target server such as which packages are installed.
Affected Products:
- Caldera Network Desktop 1.0.0
- Caldera OpenLinux 1.0.0
- Caldera OpenLinux 1.1.0
- Caldera OpenLinux Base 1.0.0
- Caldera OpenLinux Base 1.1.0
- Caldera OpenLinux Lite 1.0.0
- Caldera OpenLinux Lite 1.1.0
- Caldera OpenLinux Standard 1.0.0
- Caldera OpenLinux Standard 1.1.0
- HP HP-UX 11.0.0
- HP HP-UX 11.11.0
- HP HP-UX 11.22.0
- SGI IRIX 6.5.0
- SGI IRIX 6.5.1
- SGI IRIX 6.5.10
- SGI IRIX 6.5.11
- SGI IRIX 6.5.12
- SGI IRIX 6.5.13
- SGI IRIX 6.5.14
- SGI IRIX 6.5.15
- SGI IRIX 6.5.16
- SGI IRIX 6.5.17f
- SGI IRIX 6.5.17m
- SGI IRIX 6.5.18f
- SGI IRIX 6.5.18m
- SGI IRIX 6.5.19f
- SGI IRIX 6.5.19m
- SGI IRIX 6.5.2
- SGI IRIX 6.5.20 f
- SGI IRIX 6.5.20 m
- SGI IRIX 6.5.21 f
- SGI IRIX 6.5.21 m
- SGI IRIX 6.5.22
- SGI IRIX 6.5.3
- SGI IRIX 6.5.4
- SGI IRIX 6.5.5
- SGI IRIX 6.5.6
- SGI IRIX 6.5.7
- SGI IRIX 6.5.8
- SGI IRIX 6.5.9
- Sun Solaris 2.3.0
- Sun Solaris 2.4.0
- Sun Solaris 2.4.0_x86
- Sun Solaris 2.5.0
- Sun Solaris 2.5.0_x86
- Sun Solaris 2.5.1
- Sun Solaris 2.5.1_x86
- Sun Solaris 2.6
- Sun Solaris 2.6_x86
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.