LWN.net Logo

quota: bypass TCP Wrappers rules

Package(s):quota CVE #(s):CVE-2012-3417
Created:August 30, 2012 Updated:January 17, 2013
Description: From the CVE entry:

The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny.

Alerts:
openSUSE openSUSE-SU-2012:1058-1 2012-08-29
Oracle ELSA-2013-0120 2013-01-12
Scientific Linux SL-quot-20130116 2013-01-16
CentOS CESA-2013:0120 2013-01-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds