The hostreliableaddrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "1:1.2.8-6ubuntu1", "binary_name": "nfs-common" }, { "binary_version": "1:1.2.8-6ubuntu1", "binary_name": "nfs-kernel-server" } ] }