CVE Vulnerabilities

CVE-2007-4135

Published: Sep 05, 2007 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.2 MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

The NFSv4 ID mapper (nfsidmap) before 0.17 does not properly handle return values from the getpwnam_r function when performing a username lookup, which can cause it to report a file as being owned by root instead of nobody if the file exists on the server but not on the client.

Affected Software

Name Vendor Start Version End Version
Nfsidmap Nfsv4 * 0.16.22 (including)
Red Hat Enterprise Linux 5 RedHat nfs-utils-lib-0:1.0.8-7.2.z2 *
Libnfsidmap Ubuntu dapper *
Libnfsidmap Ubuntu devel *
Libnfsidmap Ubuntu edgy *
Libnfsidmap Ubuntu feisty *
Libnfsidmap Ubuntu gutsy *
Libnfsidmap Ubuntu hardy *
Libnfsidmap Ubuntu intrepid *
Libnfsidmap Ubuntu jaunty *
Libnfsidmap Ubuntu karmic *
Libnfsidmap Ubuntu lucid *
Libnfsidmap Ubuntu maverick *
Libnfsidmap Ubuntu natty *
Libnfsidmap Ubuntu upstream *

References