CVE Vulnerabilities

CVE-2013-20001

Published: Feb 12, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs feature, there is a silent failure to parse the IPv6 address data, and access is allowed to everyone. IPv6 restrictions from the configuration are not applied.

Affected Software

Name Vendor Start Version End Version
Openzfs Openzfs * 2.0.3 (including)
Zfs-linux Ubuntu bionic *
Zfs-linux Ubuntu esm-apps/xenial *
Zfs-linux Ubuntu esm-infra/bionic *
Zfs-linux Ubuntu esm-infra/xenial *
Zfs-linux Ubuntu focal *
Zfs-linux Ubuntu groovy *
Zfs-linux Ubuntu hirsute *
Zfs-linux Ubuntu impish *
Zfs-linux Ubuntu jammy *
Zfs-linux Ubuntu kinetic *
Zfs-linux Ubuntu lunar *
Zfs-linux Ubuntu trusty *
Zfs-linux Ubuntu upstream *
Zfs-linux Ubuntu xenial *

References