ncpfs: multiple vulnerabilities
| Package(s): | ncpfs | CVE #(s): | CVE-2010-0790 CVE-2010-0791 | ||||||||||||
| Created: | March 12, 2010 | Updated: | June 14, 2010 | ||||||||||||
| Description: | From the Mandriva advisory: sutil/ncpumount.c in ncpumount in ncpfs 2.2.6 produces certain detailed error messages about the results of privileged file-access attempts, which allows local users to determine the existence of arbitrary files via the mountpoint name (CVE-2010-0790). The (1) ncpmount, (2) ncpumount, and (3) ncplogin programs in ncpfs 2.2.6 do not properly create lock files, which allows local users to cause a denial of service (application failure) via unspecified vectors that trigger the creation of a /etc/mtab~ file that persists after the program exits (CVE-2010-0791). | ||||||||||||||
| Alerts: |
| ||||||||||||||
