First published: Tue Mar 09 2010(Updated: )
The (1) ncpmount, (2) ncpumount, and (3) ncplogin programs in ncpfs 2.2.6 do not properly create lock files, which allows local users to cause a denial of service (application failure) via unspecified vectors that trigger the creation of a /etc/mtab~ file that persists after the program exits.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ncpfs | =2.2.6 | |
=2.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0791 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2010-0791, you should upgrade to ncpfs version 2.2.7 or later, where the issue has been addressed.
CVE-2010-0791 affects the ncpmount, ncpumount, and ncplogin programs in ncpfs version 2.2.6.
CVE-2010-0791 is a local denial of service vulnerability primarily due to improper lock file creation.
No, CVE-2010-0791 can only be exploited locally by users with access to the affected programs.