First published: Tue Mar 09 2010(Updated: )
sutil/ncpumount.c in ncpumount in ncpfs 2.2.6 produces certain detailed error messages about the results of privileged file-access attempts, which allows local users to determine the existence of arbitrary files via the mountpoint name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ncpfs | =2.2.6 | |
=2.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0790 is considered a medium severity vulnerability due to its potential to reveal file existence to local users.
To fix CVE-2010-0790, upgrade to a version of ncpfs that addresses this issue, preferably later than 2.2.6.
CVE-2010-0790 affects ncpfs version 2.2.6 specifically.
Local users on a system running ncpfs 2.2.6 can be impacted by CVE-2010-0790.
CVE-2010-0790 can allow local users to determine the existence of arbitrary files through detailed error messages.