7.5

CVE-2013-20001

Exploit
An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs feature, there is a silent failure to parse the IPv6 address data, and access is allowed to everyone. IPv6 restrictions from the configuration are not applied.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenzfsOpenzfs Version <= 2.0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.08% 0.791
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/openzfs/zfs/issues/1894#issuecomment-30693652
Third Party Advisory
Exploit
https://github.com/openzfs/zfs/releases
Third Party Advisory
Release Notes
https://lists.debian.org/debian-lts-announce/2024/03/msg00019.html
https://lists.debian.org/debian-lts-announce/2025/04/msg00009.html