CVE-2005-0013: High severity ncpfs ncpfs vulnerability
Published Feb 6, 2005
·Updated
nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.
Affected Software
5 affected components
ncpfs ncpfs=2.2.1
ncpfs ncpfs=2.2.2
ncpfs ncpfs=2.2.3
ncpfs ncpfs=2.2.4
ncpfs ncpfs=2.2.5
Remediation
Patch Available
Event History
Feb 6, 2005
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0013?
CVE-2005-0013 is considered a high-severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2005-0013?
To fix CVE-2005-0013, upgrade to ncpfs version 2.2.6 or later, where the issue has been resolved.
3
Who is affected by CVE-2005-0013?
Users of ncpfs versions 2.2.1 to 2.2.5 are affected by CVE-2005-0013.
4
What type of vulnerability is CVE-2005-0013?
CVE-2005-0013 is a local privilege escalation vulnerability.
5
How does CVE-2005-0013 allow for privilege escalation?
CVE-2005-0013 allows local users to gain privileges because the NetWare client functions do not drop root privileges before executing utilities.