Vigil@nce: ncpfs, two vulnerabilities
March 2010 by Vigil@nce
A local attacker can use two vulnerabilities of ncpfs, in order to obtain information or to create a denial of service.
Severity: 1/4
Consequences: data reading, denial of service of service
Provenance: user shell
Means of attack: no proof of concept, no attack
Ability of attacker: expert (4/4)
Confidence: confirmed by the editor (5/5)
Diffusion of the vulnerable configuration: high (3/3)
Number of vulnerabilities in this bulletin: 2
Creation date: 08/03/2010
IMPACTED PRODUCTS
Unix - plateform
DESCRIPTION OF THE VULNERABILITY
The ncpmount and ncpumount utilities are used to mount a remote NCP (NetWare Core Protocol) share in a local directory. Two vulnerabilities were announced in ncpfs.
An attacker can use ncpumount, in order to detect if a file located in a restricted directory exists. [severity:1/4; CVE-2010-0790]
An attacker can set a lock on "/etc/mtab ", so users cannot mount other filesystems. [severity:1/4; CVE-2010-0791]
CHARACTERISTICS
Identifiers: CVE-2010-0790, CVE-2010-0791, VIGILANCE-VUL-9502
Url: http://vigilance.fr/vulnerability/n...





News





