6.2

CVE-2007-4135

The NFSv4 ID mapper (nfsidmap) before 0.17 does not properly handle return values from the getpwnam_r function when performing a username lookup, which can cause it to report a file as being owned by "root" instead of "nobody" if the file exists on the server but not on the client.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nfsv4Nfsidmap Version <= 0.16.22
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.258
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.2 1.9 10
AV:L/AC:H/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/26674
Patch
Vendor Advisory
http://www.novell.com/linux/security/advisories/2007_18_sr.html
Vendor Advisory
http://osvdb.org/45825
http://secunia.com/advisories/27043
Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2007:240
http://www.redhat.com/support/errata/RHSA-2007-0951.html
http://www.securityfocus.com/bid/26767
https://exchange.xforce.ibmcloud.com/vulnerabilities/36396
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9864