Vulnerability Details CVE-2010-2020
sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.9%
CVSS Severity
CVSS v2 Score 6.9
Products affected by CVE-2010-2020
-
cpe:2.3:o:freebsd:freebsd:7.2
-
cpe:2.3:o:freebsd:freebsd:8.0
-
cpe:2.3:o:freebsd:freebsd:8.1-prerelease