Back

LOW

nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE

Published Feb 26, 2014

Description

The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of nfs-utils as shipped with Red Hat Enterprise Linux 4 as it did not include include mount.nfs. It was addressed in Red Hat Enterprise Linux 5 and 6 via RHSA-2012:0310 and RHSA-2011:1534 respectively.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 26, 2014
Updated Aug 6, 2024
Reserved Apr 19, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Apr 19, 2011