- Description
- sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount request.
- Source
- secteam@freebsd.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 6.9
- Impact score
- 10
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:C/I:C/A:C
- nvd@nist.gov
- CWE-20
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:freebsd:freebsd:7.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F948527C-A01E-4315-80B6-47FACE18A34F"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:7.2:pre-release:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8B573401-DC6F-4AFE-92F5-D96F785D2107"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:7.2:stable:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "60D40129-108B-421B-9990-6C6F381C96AD"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3CF1F9EF-01AF-4708-AE02-765360AF3D66"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:8.1-prerelease:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B525B32B-417E-49C8-9847-A9F807FA67B0"
}
],
"operator": "OR"
}
]
}
]