statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
| Software | From | Fixed in |
|---|---|---|
| nfs / nfs-utils | 1.0.6 | 1.0.6.x |
| mandrakesoft / mandrake_linux_corporate_server | 2.1 | 2.1.x |
| redhat / enterprise_linux_desktop | 3.0 | 3.0.x |
| debian / debian_linux | 3.0 | 3.0.x |
| redhat / enterprise_linux | 3.0 | 3.0.x |
| mandrakesoft / mandrake_linux | 9.2 | 9.2.x |
| mandrakesoft / mandrake_linux | 10.1 | 10.1.x |
| mandrakesoft / mandrake_linux | 10.0 | 10.0.x |