Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 371477 (CVE-2011-1679) - net-fs/ncpfs: Multiple vulnerabilities (CVE-2011-{1679,1680})
Summary: net-fs/ncpfs: Multiple vulnerabilities (CVE-2011-{1679,1680})
Status: RESOLVED FIXED
Alias: CVE-2011-1679
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-06-13 20:47 UTC by GLSAMaker/CVETool Bot
Modified: 2016-01-17 17:20 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2011-06-13 20:47:31 UTC
CVE-2011-1679 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1679):
  ncpfs 2.2.6 and earlier attempts to use (1) ncpmount to append to the
  /etc/mtab file and (2) ncpumount to append to the /etc/mtab.tmp file without
  first checking whether resource limits would interfere, which allows local
  users to trigger corruption of the /etc/mtab file via a process with a small
  RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
Comment 1 Pacho Ramos gentoo-dev 2012-06-06 09:06:44 UTC
Mageia people tried to fix this:
https://bugs.mageia.org/show_bug.cgi?id=6153#c4

but they have problems to test if it still works ok after patching
Comment 2 Joshua Kinard gentoo-dev 2014-08-12 11:40:52 UTC
(In reply to Pacho Ramos from comment #1)
> Mageia people tried to fix this:
> https://bugs.mageia.org/show_bug.cgi?id=6153#c4
> 
> but they have problems to test if it still works ok after patching

I actually have NetWare installs (3.12, 4.2, and 6.5) in VMs.  I've also dabbled w/ mounting NCP shares on my main Linux box, so I'm already setup to do some partial testing.  I'll see if I take a look at this next weekend or so to see if the Mageia fix still works to mount NCP shares correctly.
Comment 3 Joshua Kinard gentoo-dev 2014-08-13 05:48:49 UTC
Fixed in ncpfs-2.2.6-r3.  Security team, all yours now.
Comment 4 Alexander Tsoy 2014-08-13 06:27:52 UTC
Patch cve-2011-1679-1680.patch is useless, because drop-mtab-support.patch from Debian (you rebased it due to the changes made by cve-... patch :) ) completely removes /etc/mtab support.
Comment 5 Joshua Kinard gentoo-dev 2014-08-13 06:52:10 UTC
(In reply to Alexander Tsoy from comment #4)
> Patch cve-2011-1679-1680.patch is useless, because drop-mtab-support.patch
> from Debian (you rebased it due to the changes made by cve-... patch :) )
> completely removes /etc/mtab support.

Ah, well, Mageia didn't really document what that patch was doing in the first place.  Let me fix it...
Comment 6 Joshua Kinard gentoo-dev 2014-08-13 07:05:04 UTC
Now it should be fixed.  Thanks for catching that :)