|
|
| |
|
| |
ncpfs: multiple vulnerabilities
| Package(s): | ncpfs |
CVE #(s): | CVE-2010-0790
CVE-2010-0791
|
| Created: | March 12, 2010 |
Updated: | June 14, 2010 |
| Description: |
From the Mandriva advisory:
sutil/ncpumount.c in ncpumount in ncpfs 2.2.6 produces certain detailed
error messages about the results of privileged file-access attempts,
which allows local users to determine the existence of arbitrary
files via the mountpoint name (CVE-2010-0790).
The (1) ncpmount, (2) ncpumount, and (3) ncplogin programs in ncpfs
2.2.6 do not properly create lock files, which allows local users
to cause a denial of service (application failure) via unspecified
vectors that trigger the creation of a /etc/mtab~ file that persists
after the program exits (CVE-2010-0791). |
| Alerts: |
|
( Log in to post comments)
|
|
|