CVE-2013-1923 — Sensitive Information Exposure in Nfs-utils
Severity
3.2LOWNVD
EPSS
0.4%
top 39.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 21
Latest updateMay 17
Description
rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks.
CVSS vector
AV:A/AC:H/C:P/I:P/A:NExploitability: 3.2 | Impact: 4.9