Vulnerability Description
ncpfs 2.2.6 allows local users to cause a denial of service, obtain sensitive information, or possibly gain privileges via symlink attacks involving the (1) ncpmount and (2) ncpumount programs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ncpfs | Ncpfs | 2.2.6 |
Related Weaknesses (CWE)
References
- http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034403.ht
- http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034422.ht
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
- http://seclists.org/fulldisclosure/2010/Mar/122
- http://secunia.com/advisories/38327Vendor Advisory
- http://secunia.com/advisories/38371Vendor Advisory
- http://www.securityfocus.com/archive/1/509893/100/0/threaded
- http://www.securityfocus.com/archive/1/509894/100/0/threaded
- http://www.securityfocus.com/bid/38563
- https://bugzilla.redhat.com/show_bug.cgi?id=532940
- https://bugzilla.redhat.com/show_bug.cgi?id=558833
- http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034403.ht
- http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034422.ht
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html
FAQ
What is CVE-2010-0788?
CVE-2010-0788 is a vulnerability with a CVSS score of 4.4 (MEDIUM). ncpfs 2.2.6 allows local users to cause a denial of service, obtain sensitive information, or possibly gain privileges via symlink attacks involving the (1) ncpmount and (2) ncpumount programs.
How severe is CVE-2010-0788?
CVE-2010-0788 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-0788?
Check the references section above for vendor advisories and patch information. Affected products include: Ncpfs Ncpfs.