CVE-2013-1923Sensitive Information Exposure in Nfs-utils

Severity
3.2LOWNVD
EPSS
0.4%
top 39.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 21
Latest updateMay 17

Description

rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks.

CVSS vector

AV:A/AC:H/C:P/I:P/A:NExploitability: 3.2 | Impact: 4.9

Affected Packages1 packages

NVDlinux-nfs/nfs-utils1.2.7+7

🔴Vulnerability Details

3
GHSA
GHSA-xr88-75g2-cjj4: rpc-gssd in nfs-utils before 12022-05-17
OSV
CVE-2013-1923: rpc-gssd in nfs-utils before 12014-01-21
CVEList
CVE-2013-1923: rpc-gssd in nfs-utils before 12014-01-21

📋Vendor Advisories

2
Red Hat
nfs-utils: rpc.gssd is vulnerable to DNS spoofing2013-04-02
Debian
CVE-2013-1923: nfs-utils - rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server na...2013

💬Community

1
Bugzilla
CVE-2013-1923 nfs-utils: rpc.gssd is vulnerable to DNS spoofing2013-04-03
CVE-2013-1923 — Sensitive Information Exposure | cvebase