SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  OS (Linux)  >  ncpfs Vendors:  kernel.org
Linux Kernel ncpfs Stack Overflow Lets Local Users Gain Elevated Privileges
SecurityTracker Alert ID:  1009094
CVE Reference:  CAN-2004-0010   (Links to External Site)
Date:  Feb 18 2004
Impact:  Execution of arbitrary code via local system, Root access via local system, User access via local system
Fix Available:  Yes   Vendor Confirmed:  Yes  
Version(s): Linux Kernel 2.6.2 and prior versions
Description:  A vulnerability was reported in the Linux 2.6 kernel in ncpfs. A local user can gain elevated privileges on the target system.

It is reported that ncp_lookup() does not validate name component lengths. A local user can cause data to overflow onto the stack, resulting in the execution of arbitrary code.

Arjan van de Ven is credited with discovering this flaw.

[Editor's note: It is not clear if the 2.4 kernel or any other kernel series is affected.]

Impact:  A local user can gain elevated privileges on the target system.
Solution:  A fix is included in Linux Kernel 2.6.3, available at:

http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.3.bz2

Vendor URL:  www.kernel.org/ (Links to External Site)
Cause:  Boundary error
Underlying OS:  Linux (Caldera/SCO), Linux (Conectiva), Linux (Debian), Linux (EnGarde), Linux (Gentoo), Linux (HP Secure OS), Linux (Immunix), Linux (Mandrake), Linux (Progeny Debian), Linux (Red Hat Enterprise), Linux (Red Hat Fedora), Linux (Red Hat Linux), Linux (SGI), Linux (Slackware), Linux (Sun), Linux (SuSE), Linux (Trustix), Linux (Turbo Linux), Linux (Xandros)

Message History:   This archive entry has one or more follow-up message(s) listed below.
Feb 18 2004 (Red Hat Issues Fix for RH Linux) Linux Kernel ncpfs Stack Overflow Lets Local Users Gain Elevated Privileges   (bugzilla@redhat.com)
Red Hat has issued a fix for Red Hat Linux 9.
Feb 18 2004 (Red Hat Issues Fix for RH Enterprise Linux) Linux Kernel ncpfs Stack Overflow Lets Local Users Gain Elevated Privileges   (bugzilla@redhat.com)
Red Hat has released a fix for Red Hat Enterprise Linux 2.1
Feb 18 2004 (SuSE Issues Fix) Linux Kernel ncpfs Stack Overflow Lets Local Users Gain Elevated Privileges   (thomas@suse.de (Thomas Biege))
SuSE has released a fix.
Feb 25 2004 (Mandrake Issues Fix) Linux Kernel ncpfs Stack Overflow Lets Local Users Gain Elevated Privileges   (Mandrake Linux Security Team <security@linux-mandrake.com>)
Mandrake has released a fix.
Feb 26 2004 (Mandrake Issues Fix for x86_64) Linux Kernel ncpfs Stack Overflow Lets Local Users Gain Elevated Privileges   (Mandrake Linux Security Team <security@linux-mandrake.com>)
Mandrake has released a fix for Corporate Server 2.1/x86_64.
Apr 16 2004 (Debian Issues Fix for 2.4.18/alpha/i386/powerpc) Linux Kernel ncpfs Stack Overflow Lets Local Users Gain Elevated Privileges   (joey@infodrom.org (Martin Schulze))
Debian has released a fix for the 2.4.18 kernel on the alpha, i386, and powerpc architectures.
May 12 2004 (Red Hat Issues Fix for RH Enterprise Linux) Linux Kernel ncpfs Stack Overflow Lets Local Users Gain Elevated Privileges   (bugzilla@redhat.com)
Red Hat has released a fix for Red Hat Enterprise Linux 3.



 Source Message Contents

Date:  Wed, 18 Feb 2004 08:07:25 -0500
Subject:  CAN-2004-0010

 

CVE: CAN-2004-0010

It is reported that a local user can gain elevated privileges by exploiting a flaw in the 
ncp_lookup() function in ncpfs.  According to the report, ncpfs is used to allow a system 
to mount volumes of NetWare servers or print to NetWare printers.

Arjan van de Ven is credited with discovering this flaw.

Red Hat provided this information.

 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2004, SecurityGlobal.net LLC