SciLinux: CVE-2007-3999 nfs-utils-lib SL5.x i386/x86_64
Summary
Date: Thu, 4 Oct 2007 10:49:43 -0500Reply-To: Connie SiehSender: Security Errata for Scientific Linux From: Connie Sieh Subject: Security ERRATA for nfs-utils-lib on SL5.x i386/x86_64Comments: To: scientific Synopsis: Important: nfs-utils-lib security updateCVE Names: CVE-2007-3999 CVE-2007-4135Details:Tenable Network Security discovered a stack buffer overflow flaw in the RPClibrary used by nfs-utils-lib. A remote unauthenticated attacker who canaccess an application linked against nfs-utils-lib could trigger this flawand cause the application to crash. On Red Hat Enterprise Linux 5 it is notpossible to exploit this flaw to run arbitrary code as the overflow isblocked by FORTIFY_SOURCE. (CVE-2007-3999)Tony Ernst from SGI has discovered a flaw in the way nfsidmap maps NFSv4unknown uids. If an unknown user ID is encountered on an NFSv4 mountedfilesystem, the files will default to being owned by 'root' rather than'nobody'. (CVE-2007-4135)SL5.xSRPMS: nfs-utils-lib-1.0.8-7.2.z2.src.rpmi386: nfs-utils-lib-1.0.8-7.2.z2.i386.rpm nfs-utils-lib-devel-1.0.8-7.2.z2.i386.rpmx86_64: nfs-utils-lib-1.0.8-7.2.z2.i386.rpm nfs-utils-lib-1.0.8-7.2.z2.x86_64.rpm nfs-utils-lib-devel-1.0.8-7.2.z2.i386.rpm nfs-utils-lib-devel-1.0.8-7.2.z2.x86_64.rpm-Connie Sieh-Troy Dawson