CVE-2013-3266

FreeBSD <9.1-RELEASE-p3 - Memory Corruption

Title source: llm
STIX 2.1

Description

The nfsrvd_readdir function in sys/fs/nfsserver/nfs_nfsdport.c in the new NFS server in FreeBSD 8.0 through 9.1-RELEASE-p3 does not verify that a READDIR request is for a directory node, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by specifying a plain file instead of a directory.

References (4)

Core 4
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2672
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/53241
Patch, Vendor Advisory vendor-advisory x_refsource_freebsd
http://www.freebsd.org/security/advisories/FreeBSD-SA-13:05.nfsserver.asc
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1028491

Scores

EPSS 0.0231
EPSS Percentile 85.0%

Details

CWE
CWE-20
Status published
Products (6)
freebsd/freebsd 8.0
freebsd/freebsd 8.1
freebsd/freebsd 8.2
freebsd/freebsd 8.3
freebsd/freebsd 9.0
freebsd/freebsd 9.1
Published May 02, 2013
Tracked Since Feb 18, 2026