Linux Kernel ncpfs Stack Overflow Lets Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1009094
|
|
CVE Reference: CAN-2004-0010
(Links to External Site)
|
Date: Feb 18 2004
|
Impact: Execution of arbitrary code via local system, Root access via local system, User access via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): Linux Kernel 2.6.2 and prior versions
|
Description: A vulnerability was reported in the Linux 2.6 kernel in ncpfs. A local user can gain elevated privileges on the target system.
It is reported that ncp_lookup() does not validate name component lengths. A local user can cause data to overflow onto the stack,
resulting in the execution of arbitrary code.
Arjan van de Ven is credited with discovering this flaw.
[Editor's note: It
is not clear if the 2.4 kernel or any other kernel series is affected.]
|
Impact: A local user can gain elevated privileges on the target system.
|
Solution: A fix is included in Linux Kernel 2.6.3, available at:
http://www.kernel.org/pub/linux/kernel/v2.6/patch-2.6.3.bz2
|
Vendor URL: www.kernel.org/ (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Linux (Caldera/SCO), Linux (Conectiva), Linux (Debian), Linux (EnGarde), Linux (Gentoo), Linux (HP Secure OS), Linux (Immunix), Linux (Mandrake), Linux (Progeny Debian), Linux (Red Hat Enterprise), Linux (Red Hat Fedora), Linux (Red Hat Linux), Linux (SGI), Linux (Slackware), Linux (Sun), Linux (SuSE), Linux (Trustix), Linux (Turbo Linux), Linux (Xandros)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 18 Feb 2004 08:07:25 -0500
Subject: CAN-2004-0010
|
CVE: CAN-2004-0010
It is reported that a local user can gain elevated privileges by exploiting a flaw in the
ncp_lookup() function in ncpfs. According to the report, ncpfs is used to allow a system
to mount volumes of NetWare servers or print to NetWare printers.
Arjan van de Ven is credited with discovering this flaw.
Red Hat provided this information.
|
|