The (1) ncpmount, (2) ncpumount, and (3) ncplogin programs in ncpfs 2.2.6 do not properly create lock files, which allows local users to cause a denial of service (application failure) via unspecified vectors that trigger the creation of a /etc/mtab~ file that persists after the program exits.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2010/Mar/122 | mailing list patch |
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html | vendor advisory |
http://www.securityfocus.com/archive/1/509893/100/0/threaded | mailing list |
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html | vendor advisory |
http://www.securityfocus.com/bid/38563 | vdb entry |
http://www.securityfocus.com/archive/1/509894/100/0/threaded | mailing list |