7.2
CVSSv2

CVE-2005-0013

Published: 02/05/2005 Updated: 19/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

nwclient.c in ncpfs prior to 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

ncpfs ncpfs 2.2.2

ncpfs ncpfs 2.2.3

ncpfs ncpfs 2.2.1

ncpfs ncpfs 2.2.4

ncpfs ncpfs 2.2.5

Vendor Advisories

Synopsis ncpfs security update Type/Severity Security Advisory: Moderate Topic An updated ncpfs package is now availableThis update has been rated as having moderate security impact by the RedHat Security Response Team Description Ncpfs is a file system that understands the Novell NetWare ...
Erik Sjölund discovered several bugs in ncpfs that provides utilities to use resources from NetWare servers of which one also applies to the stable Debian distribution Due to accessing a configuration file without further checks with root permissions it is possible to read arbitrary files For the stable distribution (woody) this problem has been ...