Input validation error in FreeBSD - CVE-2011-1739
Published: May 3, 2011 / Updated: August 11, 2020
FreeBSD
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The makemask function in mountd.c in mountd in FreeBSD 7.4 through 8.2 does not properly handle a -network field specifying a CIDR block with a prefix length that is not an integer multiple of 8, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances via an NFS mount request.