4

CVE-2012-3417

The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jan KaraLinux Diskquota Version <= 3.16
Jan KaraLinux Diskquota Version2.0
Jan KaraLinux Diskquota Version3.01
Jan KaraLinux Diskquota Version3.01 Updatepre2
Jan KaraLinux Diskquota Version3.01 Updatepre3
Jan KaraLinux Diskquota Version3.01 Updatepre4
Jan KaraLinux Diskquota Version3.01 Updatepre5
Jan KaraLinux Diskquota Version3.01 Updatepre6
Jan KaraLinux Diskquota Version3.01 Updatepre7
Jan KaraLinux Diskquota Version3.01 Updatepre8
Jan KaraLinux Diskquota Version3.01 Updatepre9
Jan KaraLinux Diskquota Version3.02
Jan KaraLinux Diskquota Version3.03
Jan KaraLinux Diskquota Version3.04
Jan KaraLinux Diskquota Version3.05
Jan KaraLinux Diskquota Version3.06
Jan KaraLinux Diskquota Version3.07
Jan KaraLinux Diskquota Version3.08
Jan KaraLinux Diskquota Version3.09
Jan KaraLinux Diskquota Version3.10
Jan KaraLinux Diskquota Version3.11
Jan KaraLinux Diskquota Version3.12
Jan KaraLinux Diskquota Version3.13
Jan KaraLinux Diskquota Version3.14
Jan KaraLinux Diskquota Version3.15
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.15% 0.863
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4 4.9 4.9
AV:N/AC:H/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://www.openwall.com/lists/oss-security/2012/07/19/2
http://www.openwall.com/lists/oss-security/2012/07/19/5
http://linuxquota.git.sourceforge.net/git/gitweb.cgi?p=linuxquota/linuxquota%3Ba=commitdiff%3Bh=0abbfe92536fa5854eb65572de0cf131f80e2387
http://rhn.redhat.com/errata/RHSA-2013-0120.html
http://sourceforge.net/tracker/?func=detail&aid=2743481&group_id=18136&atid=118136
https://bugzilla.redhat.com/show_bug.cgi?id=566717
https://hermes.opensuse.org/messages/15509723