relax insecure option on mountd From: Robert Gordon In nfs-utils 1.2.0, I noticed that the insecure option validates that the client port is a subset of IPPORT_RESERVED as opposed to just validating it is a valid reserved port. The following proposed patch would correct that issue. Acked-by: Jeff Layton Signed-off-by: Robert Gordon Signed-off-by: Steve Dickson --- utils/mountd/auth.c | 3 +-- 1 files changed, 1 insertions(+), 2 deletions(-) diff --git a/utils/mountd/auth.c b/utils/mountd/auth.c index d978742..0835d66 100644 --- a/utils/mountd/auth.c +++ b/utils/mountd/auth.c @@ -187,8 +187,7 @@ auth_authenticate_internal(struct sockaddr_in *caller, } } if (!(exp->m_export.e_flags & NFSEXP_INSECURE_PORT) && - (ntohs(caller->sin_port) < IPPORT_RESERVED/2 || - ntohs(caller->sin_port) >= IPPORT_RESERVED)) { + ntohs(caller->sin_port) >= IPPORT_RESERVED) { *error = illegal_port; return NULL; }