Vulnerability Name: | CVE-2005-0013 (CCN-19149) | ||||||||||||
Assigned: | 2005-01-30 | ||||||||||||
Published: | 2005-01-30 | ||||||||||||
Updated: | 2018-10-19 | ||||||||||||
Summary: | nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges. | ||||||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: CONFIRM Type: UNKNOWN ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6 Source: MITRE Type: CNA CVE-2005-0013 Source: CCN Type: ncpfs Web page ncpfs - Default branch Source: CCN Type: RHSA-2005-371 ncpfs security update Source: CCN Type: SECTRACK ID: 1013019 ncpfs Access Control Bug Lets Local Users Access Files and Buffer Overflow May Let Local Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1013019 Source: CCN Type: CIAC INFORMATION BULLETIN P-204 ncpfs Security Update Source: DEBIAN Type: Patch DSA-665 Source: DEBIAN Type: DSA-665 ncpfs -- missing privilege release Source: CCN Type: GLSA-200501-44 ncpfs: Multiple vulnerabilities Source: GENTOO Type: Vendor Advisory GLSA-200501-44 Source: MANDRAKE Type: UNKNOWN MDKSA-2005:028 Source: OSVDB Type: UNKNOWN 13297 Source: CCN Type: OSVDB ID: 13297 ncpfs nwclient.c Based Utilities Arbitrary Privileged File Access Source: REDHAT Type: UNKNOWN RHSA-2005:371 Source: FEDORA Type: UNKNOWN FLSA:152904 Source: BID Type: UNKNOWN 12400 Source: CCN Type: BID-12400 NCPFS Multiple Remote Vulnerabilities Source: XF Type: UNKNOWN ncpfs-nwclientscgain-privileges(19149) Source: SUSE Type: SUSE-SR:2005:003 SUSE Security Summary Report | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |