Remote Code Execution via DNS Spoofing in rpc-gssd

Remote Code Execution via DNS Spoofing in rpc-gssd

CVE-2013-1923 · LOW Severity

AV:A/AC:H/AU:N/C:P/I:P/A:N

rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks.

Learn more about our Cis Benchmark Audit For Server Software.