RPC: PCNFSD Format string

This signature detects attempts to exploit a known vulnerability in multiple implementations of rpc.pcnfsd. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

Multiple vendors' implementation of the rpc.pcnfsd service is prone to an integer overflow vulnerability. Attackers can exploit this issue to gain superuser privileges on the affected computer or to cause denial-of-service conditions. Note: This issue was previously titled 'HP-UX ONCplus Unspecified Remote Privilege Escalation Vulnerability' but has been updated to better document the underlying issue.

Affected Products

Sgi irix

Short Name
RPC:PCNFSD-FS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
RPC
Keywords
CVE-2010-1039 Format PCNFSD bid:40248 string
Release Date
08/03/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
Port
RPC/150001
False Positive
Unknown
Vendors

Sgi

Ibm

CVSS Score

10.0

Found a potential security threat?