<title>ncpfs: Buffer overflow in ncplogin and ncpmap</title>
ncpfs is vulnerable to a buffer overflow that could lead to local execution
of arbitrary code with elevated privileges.
<announced>December 15, 2004</announced>
<revised>December 15, 2004: 01</revised>
&gt;=2.2.5 unaffected
&lt;2.2.5 vulnerable
ncpfs is a NCP protocol network filesystem that allows access to
Netware services, for example to mount volumes of NetWare servers or
print to NetWare print queues.
Karol Wiesek discovered a buffer overflow in the handling of the
'-T' option in the ncplogin and ncpmap utilities, which are both
installed as SUID root by default.
A local attacker could trigger the buffer overflow by calling one
of these utilities with a carefully crafted command line, potentially
resulting in execution of arbitrary code with root privileges.
All ncpfs users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=net-fs/ncpfs-2.2.5&quot;</code>
<uri link="">Full Disclosure Advisory</uri>
<uri link="">CAN-2004-1079</uri>
