Total vulnerabilities in the database
ncpfs 2.2.6 and earlier attempts to use (1) ncpmount to append to the /etc/mtab file and (2) ncpumount to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
Software | From | Fixed in |
---|---|---|
ncpfs / ncpfs | 2.2.2 | 2.2.2.x |
ncpfs / ncpfs | 2.2.4 | 2.2.4.x |
ncpfs / ncpfs | 2.2.5 | 2.2.5.x |
ncpfs / ncpfs | - | 2.2.6.x |
ncpfs / ncpfs | 2.2.1 | 2.2.1.x |
ncpfs / ncpfs | 2.2.3 | 2.2.3.x |