Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.56708
Category:Fedora Local Security Checks
Title:Fedora Legacy Security Advisory FLSA-2006:152904
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory FLSA-2006:152904.

Buffer overflows were found in the nwclient program. An attacker, using
a long -T option, could possibly execute arbitrary code and gain
privileges. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-2004-1079 to this issue.

A bug was found in the way ncpfs handled file permissions. ncpfs did not
sufficiently check if the file owner matched the user attempting to
access the file, potentially violating the file permissions. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
name CVE-2005-0013 to this issue.

A buffer overflow was found in the ncplogin program. A remote malicious
NetWare server could execute arbitrary code on a victim's machine. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CVE-2005-0014 to this issue.

All users of ncpfs are advised to upgrade to this updated package, which
contains backported fixes for these issues.

Affected platforms:
Redhat 7.3
Redhat 9
Fedora Core 1
Fedora Core 2
Fedora Core 3

Solution:
http://www.securityspace.com/smysecure/catid.html?in=FLSA-2006:152904

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-1079
BugTraq ID: 11945
http://www.securityfocus.com/bid/11945
Bugtraq: 20041129 ncpfs buffer overflow (Google Search)
http://marc.info/?l=bugtraq&m=110175523207437&w=2
http://www.securityfocus.com/archive/1/433927/100/0/threaded
http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029563.html
http://www.gentoo.org/security/en/glsa/glsa-200412-09.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2005:028
XForce ISS Database: ncpfs-nwclientc-bo(18283)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18283
Common Vulnerability Exposure (CVE) ID: CVE-2005-0013
BugTraq ID: 12400
http://www.securityfocus.com/bid/12400
Debian Security Information: DSA-665 (Google Search)
http://www.debian.org/security/2005/dsa-665
http://www.gentoo.org/security/en/glsa/glsa-200501-44.xml
http://www.osvdb.org/13297
http://www.redhat.com/support/errata/RHSA-2005-371.html
http://securitytracker.com/id?1013019
Common Vulnerability Exposure (CVE) ID: CVE-2005-0014
http://www.osvdb.org/13298
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.