CVE-2011-1679

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
10/04/2011
Last modified:
11/04/2025

Description

ncpfs 2.2.6 and earlier attempts to use (1) ncpmount to append to the /etc/mtab file and (2) ncpumount to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ncpfs:ncpfs:*:*:*:*:*:*:*:* 2.2.6 (including)
cpe:2.3:a:ncpfs:ncpfs:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ncpfs:ncpfs:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:ncpfs:ncpfs:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:ncpfs:ncpfs:2.2.4:*:*:*:*:*:*:*
cpe:2.3:a:ncpfs:ncpfs:2.2.5:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools