Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Date: Wed, 19 Sep 2007 16:46:34 -0500 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for nfs-utils-lib on SL4.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Important: nfs-utils-lib security update Issue date: 2007-09-19 CVE Names: CVE-2007-3999 Tenable Network Security discovered a stack buffer overflow flaw in the RPC library used by nfs-utils-lib. A remote unauthenticated attacker who can access an application linked against nfs-utils-lib could trigger this flaw and cause the application to crash. On Red Hat Enterprise Linux 4 it is not possible to exploit this flaw to run arbitrary code as the overflow is blocked by FORTIFY_SOURCE. (CVE-2007-3999) SL 4.x SRPMS: nfs-utils-lib-1.0.6-8.z1.src.rpm i386: nfs-utils-lib-1.0.6-8.z1.i386.rpm nfs-utils-lib-devel-1.0.6-8.z1.i386.rpm x86_64: nfs-utils-lib-1.0.6-8.z1.x86_64.rpm nfs-utils-lib-devel-1.0.6-8.z1.x86_64.rpm -Connie Sieh -Troy Dawson