Name | CVE-2006-0043 |
Description | Buffer overflow in the realpath function in nfs-server rpc.mountd, as used in SUSE Linux 9.1 through 10.0, allows local users to execute arbitrary code via unspecified vectors involving mount requests and symlinks. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-975-1 |
Debian Bugs | 350020 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
nfs-user-server | source | woody | 2.2beta47-12woody1 | DSA-975-1 | ||
nfs-user-server | source | sarge | 2.2beta47-20sarge2 | DSA-975-1 | ||
nfs-user-server | source | (unstable) | 2.2beta47-22 | high | 350020 |
nfs-utils (kernel NFS server) is not affected
(it uses PATH_MAX for the buffer passed to realpath).