FreeBSD-SA-10:06Vendor advisory
http://security.freebsd.org/advisories/FreeBSD-SA-10:06.nfsclient.asc CVE-2010-2020
FreeBSD 8.0/7.3/7.2 - 'nfs_mount()' Local Privilege Escalation
Record summary
CVE-2010-2020 has a selected CVSS score of 6.9; EIP currently links 2 catalogued exploits.
Description
sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBFreeBSD 8.0/7.3/7.2 - 'nfs_mount()' Local Privilege EscalationExploitDB exploitby Patroklos ArgyroudisNot analyzed1 file
ExploitDBFreeBSD - 'mountnfs()' Denial of ServiceExploitDB exploitby Patroklos ArgyroudisNot analyzed1 file
References
51024039vdb entry
http://securitytracker.com/id?1024039 14002exploit
http://www.exploit-db.com/exploits/14002 14003exploit
http://www.exploit-db.com/exploits/14003 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-2020