Debian Nfs-Utils vulnerabilities
9 known vulnerabilities affecting debian/nfs-utils.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM4LOW2
Vulnerabilities
Page 1 of 1
CVE-2019-3689P3MEDIUMCVSS 5.1fixed in nfs-utils 1:1.3.4-3 (bookworm)2019
CVE-2019-3689 [MEDIUM] CVE-2019-3689: nfs-utils - The nfs-utils package in SUSE Linux Enterprise Server 12 before and including ve...
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with roo
debian
CVE-2008-4552P3HIGHCVSS 7.5fixed in nfs-utils 1:1.1.3-1 (bookworm)2008
CVE-2008-4552 [HIGH] CVE-2008-4552: nfs-utils - The good_client function in nfs-utils 1.0.9, and possibly other versions before ...
The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroups and allows remote attackers to bypass intended access restrictions.
Scope: local
bookworm: resolved (fixed in 1:1.1.3-1)
bullseye: resolved (fixed in 1:1.1.3-1)
forky: r
debian
CVE-2025-12801P3MEDIUMCVSS 6.5fixed in nfs-utils 1:2.8.6-1 (forky)2025
CVE-2025-12801 [MEDIUM] CVE-2025-12801: nfs-utils - A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-util...
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless
debian
CVE-2011-2500P3HIGHCVSS 7.5fixed in nfs-utils 1:1.2.4-1 (bookworm)2011
CVE-2011-2500 [HIGH] CVE-2011-2500: nfs-utils - The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils be...
The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.
Scope: local
bookworm: resolved (fixed in 1:1.2.4-1)
bullseye: resolved (fixed in 1:1.2.4-1)
forky: resolved (fixed in 1
debian
CVE-2003-0252P4CRITICALCVSS 9.8fixed in nfs-utils 1:1.0.3-2 (bookworm)2003
CVE-2003-0252 [CRITICAL] CVE-2003-0252: nfs-utils - Off-by-one error in the xlog function of mountd in the Linux NFS utils package (...
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.
Scope: local
bookworm: resolved (fixed in 1:1.0.3-2)
bullseye: resolved (fixed in 1:1.0.3-2)
forky: resolv
debian
CVE-2004-1014P4MEDIUMCVSS 5.0fixed in nfs-utils 1:1.0.6-3.1 (bookworm)2004
CVE-2004-1014 [MEDIUM] CVE-2004-1014: nfs-utils - statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which a...
statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
Scope: local
bookworm: resolved (fixed in 1:1.0.6-3.1)
bullseye: resolved (fixed in 1:1.0.6-3.1)
forky: resolved (fixed in 1:1.0.6-3.1)
sid: resolved (fixed i
debian
CVE-2013-1923P4LOWCVSS 3.2fixed in nfs-utils 1:1.2.8-1 (bookworm)2013
CVE-2013-1923 [LOW] CVE-2013-1923: nfs-utils - rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server na...
rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks.
Scope: local
bookworm: resolved (fixed in 1:1.2.8-1)
bullseye: resolved (fixed in 1:1.2.8-1)
forky: resolved (fixed in 1:1.2.8-1)
sid: resolved (fixed in 1:1.2
debian
CVE-2004-0154P4MEDIUMCVSS 5.0fixed in nfs-utils 1:1.0.5-3 (bookworm)2004
CVE-2004-0154 [MEDIUM] CVE-2004-0154: nfs-utils - rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a...
rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.
Scope: local
bookworm: resolved (fixed in 1:1.0.5-3)
bullseye: resolved (fixed in 1:1.0.5-3)
forky: resolved (fixed in 1:1.0.5-3)
sid: resol
debian
CVE-2011-1749P4LOWCVSS 3.3fixed in nfs-utils 1:1.2.3-3 (bookworm)2011
CVE-2011-1749 [LOW] CVE-2011-1749: nfs-utils - The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in ...
The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
Scope: local
bookworm: resolved (f
debian