NFS: NFS-UTILS XLOG Off-By-One
This signature detects attempts to exploit an off-by-one vulnerability in the Linux NFS implementation. Attackers can send malformed logging information in a maliciously crafted request to crash the server or execute arbitrary code.
Extended Description
A remote exploitable buffer overrun vulnerability has been reported in the xlog component of nfs-utils. It is possible to exploit this issue via mountd. It has been reported that exploitation of this issue will most likely result in a denial of service. There is a possibility that this issue could be exploited to run arbitrary code in the context of mountd, which runs as root.
Affected Products
Sun cobalt_raq_xtr,Nfs nfs-utils
References
BugTraq: 8179
CVE: CVE-2003-0252
URL: http://www.redhat.com/support/errata/RHSA-2003-206.html http://www.kb.cert.org/vuls/id/258564
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Sun
Sco
Nfs
10.0