Severity: Unknown
Affected Package: nfsserver
Summary: NFS server uses client-supplied credentials for anonymous export mapping
When -network or -host restrictions are configured on an NFS export, the kernel incorrectly uses client-supplied credentials instead of the credential configured in exports(5) when filling out the anonymous credential. A remote client may therefore supply privileged credentials (such as root) when accessing files under the share, bypassing normal access checks. Patch obtained from FreeBSD.
No specific recommendations provided.
Aliases: CVE-2013-4851
Published: July 28, 2013
Last Modified: July 28, 2013