CVE-2008-4552

Source
https://nvd.nist.gov/vuln/detail/CVE-2008-4552
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2008-4552.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2008-4552
Related
Published
2008-10-14T20:00:01Z
Modified
2024-09-18T01:00:21Z
Summary
[none]
Details

The goodclient function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hostsctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroups and allows remote attackers to bypass intended access restrictions.

References

Affected packages

Debian:11 / nfs-utils

Package

Name
nfs-utils
Purl
pkg:deb/debian/nfs-utils?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.1.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / nfs-utils

Package

Name
nfs-utils
Purl
pkg:deb/debian/nfs-utils?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.1.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / nfs-utils

Package

Name
nfs-utils
Purl
pkg:deb/debian/nfs-utils?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.1.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}