First published: Mon May 02 2005(Updated: )
nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ncpfs | =2.2.1 | |
ncpfs | =2.2.2 | |
ncpfs | =2.2.3 | |
ncpfs | =2.2.4 | |
ncpfs | =2.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0013 is considered a high-severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2005-0013, upgrade to ncpfs version 2.2.6 or later, where the issue has been resolved.
Users of ncpfs versions 2.2.1 to 2.2.5 are affected by CVE-2005-0013.
CVE-2005-0013 is a local privilege escalation vulnerability.
CVE-2005-0013 allows local users to gain privileges because the NetWare client functions do not drop root privileges before executing utilities.