RedHat has issued this advisory on December 6: https://rhn.redhat.com/errata/RHSA-2011-1534.html We already fixed CVE-2011-1749, but the other one, a flaw in IP address authentication, was missed. Cauldron is not vulnerable.
CC: (none) => anssi.hannula
CC: (none) => guillomovitch
I just submitted a patched version to core/updates_testing.
Advisory: ======================== Updated nfs-utils packages fix security vulnerability: A flaw was found in the way nfs-utils performed IP based authentication of mount requests. In configurations where a directory was exported to a group of systems using a DNS wildcard or NIS (Network Information Service) netgroup, an attacker could possibly gain access to other directories exported to a specific host or subnet, bypassing intended access restrictions. (CVE-2011-2500) References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2500 https://rhn.redhat.com/errata/RHSA-2011-1534.html ======================== Updated packages in core/updates_testing: ======================== nfs-utils-1.2.3-2.3.mga1 nfs-utils-clients-1.2.3-2.3.mga1 from nfs-utils-1.2.3-2.3.mga1.src.rpm
Assignee: bugsquad => qa-bugs
Testing complete on i586 for the srpm nfs-utils-1.2.3-2.3.mga1.src.rpm Just testing I can access shares from a VirtualBox guest. Both host and guest are running Mageia 1 with the updated nfs packages.
CC: (none) => davidwhodgins
Testing ok on x86_64 (take some time to remember how it works) Suggested Advisory: ------------- Updated nfs-utils packages fix security vulnerability: A flaw was found in the way nfs-utils performed IP based authentication of mount requests. In configurations where a directory was exported to a group of systems using a DNS wildcard or NIS (Network Information Service) netgroup, an attacker could possibly gain access to other directories exported to a specific host or subnet, bypassing intended access restrictions. (CVE-2011-2500) References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2500 https://rhn.redhat.com/errata/RHSA-2011-1534.html https://bugs.mageia.org/show_bug.cgi?id=5270 ------------- SRPM: nfs-utils-1.2.3-2.3.mga1.src.rpm Could sysadmin please push from core/updates_testing to core/updates Thankyou!
Keywords: (none) => validated_updateCC: (none) => sysadmin-bugs
Update pushed
Status: NEW => RESOLVEDCC: (none) => tmbResolution: (none) => FIXED