CVE-2004-1014

Publication date 10 January 2005

Last updated 24 July 2024


Ubuntu priority

statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.

Status

Package Ubuntu Release Status
cyrus21-imapd 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected
nfs-utils 7.04 feisty
Fixed 1.0.7-3ubuntu2
6.10 edgy
Fixed 1.0.7-3ubuntu2
6.06 LTS dapper
Fixed 1.0.7-3ubuntu2

References

Related Ubuntu Security Notices (USN)

    • USN-36-1
    • NFS statd vulnerability
    • 1 December 2004

Other references