NFS cache poisoning |
---|
Risk Level: | Low | Check or Attack Name: nfsCache |
---|---|---|
Platforms: | BSD, Linux, SunOS: 4.1.3 and earlier, Solaris: 2.5.1 and below | |
Description: | Unauthorized data insertion in the NFS cache has either been attempted or was successful. For performance reasons, NFS servers cache responses to old queries in the event the same query is received twice. Typically, NFS servers only check the RPC program number, procedure number, source address, and transaction ID. Since the authentication parameters and the procedure arguments are not checked, in some cases, an attacker can taint the cache, enabling NFS servers to insert malicious information. |
|
Remedy: | No fix information is available at this time. |
|
References: |
Know Your Risks |