CVE-2013-6410

nbd < 3.5 - Unauthenticated Access Control Bypass via Partial IP Address Match

Title source: llm
STIX 2.1

Description

nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partial match in the authfile configuration file.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/64002
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2676-1
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/11/29/4
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2806

Scores

EPSS 0.0254
EPSS Percentile 83.3%

Details

CWE
CWE-264
Status published
Products (45)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 14.10
canonical/ubuntu_linux 15.04
debian/debian_linux 6.0
debian/debian_linux 7.0
wouter_verhelst/nbd 2.7.5
wouter_verhelst/nbd 2.8.0
wouter_verhelst/nbd 2.8.2
wouter_verhelst/nbd 2.8.4
... and 35 more
Published Dec 07, 2013
Tracked Since Feb 18, 2026