CVE-2011-1680: Medium severity ncpfs vulnerability
Published Apr 10, 2011
·Updated
ncpmount in ncpfs 2.2.6 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.
Affected Software
6 affected components
ncpfs ncpfs<=2.2.6
ncpfs ncpfs=2.2.1
ncpfs ncpfs=2.2.2
ncpfs ncpfs=2.2.3
ncpfs ncpfs=2.2.4
ncpfs ncpfs=2.2.5
Event History
Apr 10, 2011
CVE Published
via MITRE·01:29 AM
Data Sourced
via MITRE·01:29 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1680?
CVE-2011-1680 is considered to have an unspecified impact and local attack vectors.
2
How do I fix CVE-2011-1680?
To mitigate CVE-2011-1680, update ncpfs to version 2.2.7 or later, where this vulnerability has been addressed.
3
What versions of ncpfs are affected by CVE-2011-1680?
CVE-2011-1680 affects ncpfs versions 2.2.6 and earlier.
4
Is there a workaround for CVE-2011-1680?
A potential workaround for CVE-2011-1680 is to manually remove the /etc/mtab~ lock file after a failed mount attempt.
5
What systems are vulnerable to CVE-2011-1680?
Systems running ncpfs versions up to 2.2.6 may be vulnerable to CVE-2011-1680.