nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ncpfs | Ncpfs | 2.2.1 (including) | 2.2.1 (including) |
Ncpfs | Ncpfs | 2.2.2 (including) | 2.2.2 (including) |
Ncpfs | Ncpfs | 2.2.3 (including) | 2.2.3 (including) |
Ncpfs | Ncpfs | 2.2.4 (including) | 2.2.4 (including) |
Ncpfs | Ncpfs | 2.2.5 (including) | 2.2.5 (including) |
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
Red Hat Enterprise Linux ES version 2.1 | RedHat | * | |
Red Hat Linux Advanced Workstation 2.1 | RedHat | * | |
Ncpfs | Ubuntu | dapper | * |
Ncpfs | Ubuntu | devel | * |
Ncpfs | Ubuntu | edgy | * |
Ncpfs | Ubuntu | feisty | * |