CVE-2010-0790: Infoleak
Published Mar 9, 2010
·Updated
sutil/ncpumount.c in ncpumount in ncpfs 2.2.6 produces certain detailed error messages about the results of privileged file-access attempts, which allows local users to determine the existence of arbitrary files via the mountpoint name.
Affected Software
1 affected component
ncpfs ncpfs=2.2.6
Remediation
Patch Available
Event History
Mar 9, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Mar 10, 2010
Data Sourced
via NVD·08:13 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0790?
CVE-2010-0790 is considered a medium severity vulnerability due to its potential to reveal file existence to local users.
2
How do I fix CVE-2010-0790?
To fix CVE-2010-0790, upgrade to a version of ncpfs that addresses this issue, preferably later than 2.2.6.
3
What does CVE-2010-0790 affect?
CVE-2010-0790 affects ncpfs version 2.2.6 specifically.
4
Who is impacted by CVE-2010-0790?
Local users on a system running ncpfs 2.2.6 can be impacted by CVE-2010-0790.
5
What exploit can occur due to CVE-2010-0790?
CVE-2010-0790 can allow local users to determine the existence of arbitrary files through detailed error messages.