CVE-2004-0946Improper Restriction of Operations within the Bounds of a Memory Buffer in Nfs-utils

6 documents6 sources
Severity
10.0CRITICALNVD
EPSS
20.8%
top 4.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateApr 29

Description

rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attackers to execute arbitrary code via a crafted NFS request.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

Also affects: Enterprise Linux 3.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wq89-rrp5-4864: rquotad in nfs-utils (rquota_server2022-04-29
CVEList
CVE-2004-0946: rquotad in nfs-utils (rquota_server2004-12-22

📋Vendor Advisories

2
Red Hat
security flaw2004-11-22
Debian
CVE-2004-0946: nfs-utils - rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures d...2004

💬Community

1
Bugzilla
CVE-2004-0946 security flaw2018-08-16
CVE-2004-0946 — NFS Nfs-utils vulnerability | cvebase