Executive brief
A vulnerability in the rpc.mountd service, which manages network file sharing, allows remote individuals to probe a server for specific files. By attempting to mount a file, an attacker can determine if it exists based on the error messages returned by the system. This information disclosure can be used to map out sensitive file locations or verify the presence of specific software and configurations on the target system.
Technical details
The rpc.mountd daemon in various Unix-like operating systems is susceptible to an information disclosure vulnerability. The service returns distinct error messages when a remote user attempts to mount a path, differentiating between paths that do not exist and paths that exist but are not exported or accessible. A remote, unauthenticated attacker can exploit this behavior to conduct file enumeration across the server's filesystem. This is a side-channel attack via error message analysis that requires network access to the RPC mount service.
Affected products
- Linux Foundation Linux
- Digital Equipment Corporation (DEC) Ultrix
Timeline
- 1997-08-24: disclosed