CVE Vulnerabilities

CVE-2007-4135

Published: Sep 05, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.2 MEDIUM
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The NFSv4 ID mapper (nfsidmap) before 0.17 does not properly handle return values from the getpwnam_r function when performing a username lookup, which can cause it to report a file as being owned by root instead of nobody if the file exists on the server but not on the client.

Affected Software

NameVendorStart VersionEnd Version
NfsidmapNfsv4*0.16.22 (including)
Red Hat Enterprise Linux 5RedHatnfs-utils-lib-0:1.0.8-7.2.z2*
LibnfsidmapUbuntudapper*
LibnfsidmapUbuntudevel*
LibnfsidmapUbuntuedgy*
LibnfsidmapUbuntufeisty*
LibnfsidmapUbuntugutsy*
LibnfsidmapUbuntuhardy*
LibnfsidmapUbuntuintrepid*
LibnfsidmapUbuntujaunty*
LibnfsidmapUbuntukarmic*
LibnfsidmapUbuntulucid*
LibnfsidmapUbuntumaverick*
LibnfsidmapUbuntunatty*
LibnfsidmapUbuntuupstream*

References