CVE-2010-2020
MEDIUM 6.9EPSS 0.9%
sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount request.
- CVSS v2.0
- 6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 0.87% chance of exploitation in the next 30 days, 56th percentile
- Published
- 2010-05-28
- Updated
- 2024-08-07