Input validation error in FreeBSD - CVE-2011-1739

 

Input validation error in FreeBSD - CVE-2011-1739

Published: May 3, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45088
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-1739
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The makemask function in mountd.c in mountd in FreeBSD 7.4 through 8.2 does not properly handle a -network field specifying a CIDR block with a prefix length that is not an integer multiple of 8, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances via an NFS mount request.


Affected software

FreeBSD

How to mitigate CVE-2011-1739

Install update from vendor's website.


External References

Related Security Bulletins