{"id":"DEBIAN-CVE-2012-3417","details":"The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny.","modified":"2026-09-23T06:47:40.963277709Z","published":"2012-08-13T20:55:08.867Z","upstream":["CVE-2012-3417"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2012-3417"}],"affected":[{"package":{"name":"quota","ecosystem":"Debian:12","purl":"pkg:deb/debian/quota?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.00~pre1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2012-3417.json"}},{"package":{"name":"quota","ecosystem":"Debian:13","purl":"pkg:deb/debian/quota?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.00~pre1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2012-3417.json"}},{"package":{"name":"quota","ecosystem":"Debian:14","purl":"pkg:deb/debian/quota?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.00~pre1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2012-3417.json"}}],"schema_version":"1.9.0"}