Executive Summary

Informations
NameCVE-2010-0296First vendor Publication2010-06-01
VendorCveLast vendor Modification2011-10-25

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score7.2Attack RangeLocal
Cvss Impact Score10Attack ComplexityLow
Cvss Expoit Score3.9AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0296

CWE : Common Weakness Enumeration

idName
CWE-20Improper Input Validation

CPE : Common Platform Enumeration

TypeDescriptionCount
Application39

Open Source Vulnerability Database (OSVDB)

idDescription
65078GNU C Library misc/mntent_r.c encode_name Macro Crafted Mount Request Local DoS

Internal Sources (Detail)

SourceUrl
BUGTRAQhttp://www.securityfocus.com/archive/1/archive/1/520102/100/0/threaded
CONFIRMhttp://frugalware.org/security/662
http://sourceware.org/git/?p=glibc.git;a=commit;h=ab00f4eac8f4932211259ff87be...
http://www.vmware.com/security/advisories/VMSA-2011-0012.html
https://bugzilla.redhat.com/show_bug.cgi?id=559579
DEBIANhttp://www.debian.org/security/2010/dsa-2058
GENTOOhttp://security.gentoo.org/glsa/glsa-201011-01.xml
MANDRIVAhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:111
http://www.mandriva.com/security/advisories?name=MDVSA-2010:112
REDHAThttp://www.redhat.com/support/errata/RHSA-2011-0412.html
SECTRACKhttp://securitytracker.com/id?1024043
SECUNIAhttp://secunia.com/advisories/39900
http://secunia.com/advisories/43830
http://secunia.com/advisories/46397
UBUNTUhttp://www.ubuntu.com/usn/USN-944-1
VUPENhttp://www.vupen.com/english/advisories/2010/1246
http://www.vupen.com/english/advisories/2011/0863
XFhttp://xforce.iss.net/xforce/xfdb/59240

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2013-05-10 23:17:02
  • Multiple Updates