← Back

CVE-2013-6410

nvd nist
Published: Dec 7, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partial match in the authfile configuration file.

Affected (45)

Nbd
1 product
Debian Linux
1 product
Ubuntu Linux
Configuration A
39 vulnerable
Vulnerable SoftwareAffected Versions
Wouter Verhelst
Up to 3.4
Version 2.7.5
Version 2.8.0
Version 2.8.2
Version 2.8.4
Version 2.8.5
Version 2.8.6
Version 2.8.7
Version 2.9.0
Version 2.9.10
Version 2.9.11
Version 2.9.12
Version 2.9.13
Version 2.9.14
Version 2.9.15
Version 2.9.16
Version 2.9.17
Version 2.9.18
Version 2.9.19
Version 2.9.1
Version 2.9.20
Version 2.9.21
Version 2.9.22
Version 2.9.23
Version 2.9.24
Version 2.9.25
Version 2.9.2
Version 2.9.3
Version 2.9.4
Version 2.9.5
Version 2.9.6
Version 2.9.7
Version 2.9.8
Version 2.9.9
Version 3.0
Version 3.1.1
Version 3.1
Version 3.2
Version 3.3
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 6.0
Version 7.0
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 14.10
Version 15.04

Related CWEs

References (10)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.