We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6759

NFS client accepts file names containing path separators



Assignerfreebsd
Reserved2024-07-15
Published2024-08-11
Updated2024-08-16

Description

When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, "/". This allows readdir(3) and related functions to return filesystem entries with names containing additional path components. The lack of validation described above gives rise to a confused deputy problem. For example, a program copying files from an NFS mount could be tricked into copying from outside the intended source directory, and/or to a location outside the intended destination directory.

Product status

Default status
unknown

14.1-RELEASE before p3
affected

14.0-RELEASE before p9
affected

13.3-RELEASE before p5
affected

Credits

Apple Security Engineering and Architecture (SEAR) finder

References

https://security.freebsd.org/advisories/FreeBSD-SA-24:07.nfsclient.asc vendor-advisory

cve.org CVE-2024-6759

nvd.nist.gov CVE-2024-6759

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-6759
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.