Multiple Vendor Statd Buffer Overflow Vulnerability

Statd is the RPC NFS status daemon. It is used to communicate status information to other services or host.

The version of statd shipped with many unix implementations contains a buffer overflow condition. This overflow condition exists in the handling of 'SM_MON' RPC requests.

Any attacker to successfully exploit this vulnerability would gain root privileges on the target host.


 

Privacy Statement
Copyright 2010, SecurityFocus