CVE-2007-4135

Publication date 5 September 2007

Last updated 24 July 2024


Ubuntu priority

Description

The NFSv4 ID mapper (nfsidmap) before 0.17 does not properly handle return values from the getpwnam_r function when performing a username lookup, which can cause it to report a file as being owned by "root" instead of "nobody" if the file exists on the server but not on the client.

Read the notes from the security team

Status

Package Ubuntu Release Status
libnfsidmap 11.04 natty
Fixed 0.19-0
10.10 maverick
Fixed 0.19-0
10.04 LTS lucid
Fixed 0.19-0
9.10 karmic
Fixed 0.19-0
9.04 jaunty
Fixed 0.19-0
8.10 intrepid
Fixed 0.19-0
8.04 LTS hardy
Fixed 0.19-0
7.10 gutsy
Fixed 0.19-0
7.04 feisty
Fixed 0.18-0build1
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life

Notes


jdstrand

fix in RHSA-2007:0951-01


Access our resources on patching vulnerabilities