Vulnerable Systems:
* net-fs/nfs-utils all versions prior to 1.0.6-r6
Immune Systems:
* net-fs/nfs-utils version 1.0.6-r6 and above.
Arjan van de Ven has discovered a buffer overflow on 64-bit architectures in 'rquota_server.c' of nfs-utils (CAN-2004-0946).
A remotely exploitable flaw on all architectures also exists in the 'statd.c' file of nfs-utils (CAN-2004-1014), which can be triggered by a mishandled SIGPIPE.
A remote attacker could potentially cause a Denial of Service, or even execute arbitrary code (64-bit architectures only) on a remote NFS server.
Workaround:
There is no known workaround at this time.
Resolution:
All nfs-utils users should upgrade to the latest version.