CVE-2004-1014

9 documents8 sources
Severity
5.0MEDIUM
EPSS
2.5%
top 14.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateApr 29

Description

statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages5 packages

Also affects: Debian Linux 3.0, Enterprise Linux 3.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jx7p-442j-f3rh: statd in nfs-utils 12022-04-29
OSV
CVE-2004-1014: statd in nfs-utils 12005-01-10
CVEList
CVE-2004-1014: statd in nfs-utils 12004-12-08

📋Vendor Advisories

3
Red Hat
security flaw2004-12-01
Ubuntu
NFS statd vulnerability2004-12-01
Debian
CVE-2004-1014: nfs-utils - statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which a...2004

💬Community

1
Bugzilla
CVE-2004-1014 security flaw2018-08-16