The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.
| Software | From | Fixed in |
|---|---|---|
| linux-nfs / nfs-utils | - | 1.2.3.x |
| linux-nfs / nfs-utils | 1.2.2 | 1.2.2.x |
| linux-nfs / nfs-utils | 1.2.1 | 1.2.1.x |
| linux-nfs / nfs-utils | 1.2.0 | 1.2.0.x |