Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-3266
HistoryMay 02, 2013 - 12:00 a.m.

CVE-2013-3266

2013-05-0200:00:00
ubuntu.com
ubuntu.com
7

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.103 Low

EPSS

Percentile

95.0%

The nfsrvd_readdir function in sys/fs/nfsserver/nfs_nfsdport.c in the new
NFS server in FreeBSD 8.0 through 9.1-RELEASE-p3 does not verify that a
READDIR request is for a directory node, which allows remote attackers to
cause a denial of service (memory corruption) or possibly execute arbitrary
code by specifying a plain file instead of a directory.

Bugs

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.103 Low

EPSS

Percentile

95.0%