« Volver al listado

CVE-2013-1923

Estado: ModificadaBaja (3.2)—

rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-1923",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.2,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:H/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.2,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-01-21T18:55:09.367",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2013-06/msg00142.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2013-06/msg00146.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2013-06/msg00172.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://marc.info/?l=linux-nfs&m=136491998607561&w=2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://marc.info/?l=linux-nfs&m=136500502805121&w=2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/58854",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=948072",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/85331",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2013-06/msg00142.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2013-06/msg00146.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2013-06/msg00172.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=linux-nfs&m=136491998607561&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=linux-nfs&m=136500502805121&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/58854",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=948072",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/85331",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks."
    },
    {
      "lang": "es",
      "value": "rpc-gssd en nfs-utils anterior a la versión 1.2.8 realiza resoluciones inversas de DNS en nombres de servidor durante la autenticación GSSAPI, lo que podría permitir a atacantes remotos leer archivos restringidos del mismo modo a través de ataques de falsificación de DNS."
    }
  ],
  "lastModified": "2026-06-16T23:52:24.523",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:linux-nfs:nfs-utils:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D711F9E-A267-44C2-B82D-77F63B53E3E6",
              "versionEndIncluding": "1.2.7"
            },
            {
              "criteria": "cpe:2.3:a:linux-nfs:nfs-utils:1.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EAF1C0B-DB17-49CE-9E5C-6D8F4ED9DA73"
            },
            {
              "criteria": "cpe:2.3:a:linux-nfs:nfs-utils:1.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4F6F79C-FA8A-486E-9541-83D57052324D"
            },
            {
              "criteria": "cpe:2.3:a:linux-nfs:nfs-utils:1.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24A01AF1-E09A-4064-815F-3672B96B03BD"
            },
            {
              "criteria": "cpe:2.3:a:linux-nfs:nfs-utils:1.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AD74E58-7ACB-43BA-8B08-BCD543063B16"
            },
            {
              "criteria": "cpe:2.3:a:linux-nfs:nfs-utils:1.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6072D90D-6144-45F3-B48A-833EA441D089"
            },
            {
              "criteria": "cpe:2.3:a:linux-nfs:nfs-utils:1.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51C825D9-5B4E-4DB1-9F2D-BC45C24BA320"
            },
            {
              "criteria": "cpe:2.3:a:linux-nfs:nfs-utils:1.2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD63FB82-B020-46BA-B9DB-D3B90863133D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}