CVE-2010-0788

ncpfs 2.2.6 - Symlink Attack via ncpmount and ncpumount

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-0788. PoCs published by super.

AI-analyzed exploit summary This exploit leverages a symlink attack in ncpfs to read shadow files by manipulating the ~/.nwclient file during mount operations. It iterates over /etc/*shadow* files and attempts to display their contents via a crafted function.

Description

ncpfs 2.2.6 allows local users to cause a denial of service, obtain sensitive information, or possibly gain privileges via symlink attacks involving the (1) ncpmount and (2) ncpumount programs.

Exploits (1)

exploitdb WORKING POC VERIFIED
by super · bashlocallinux
https://www.exploit-db.com/exploits/779

This exploit leverages a symlink attack in ncpfs to read shadow files by manipulating the ~/.nwclient file during mount operations. It iterates over /etc/*shadow* files and attempts to display their contents via a crafted function.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: ncpfs (versions prior to fix for CVE-2010-0788)
No auth needed
Prerequisites: ncpfs installed · access to a system with /etc/shadow or similar files · ncpmount utility available
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (12)

Core 12
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38371
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2010/Mar/122
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=558833
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034422.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38327
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/509893/100/0/threaded
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034403.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=532940
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38563
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/509894/100/0/threaded

Scores

EPSS 0.0067
EPSS Percentile 47.3%

Details

CWE
CWE-59
Status published
Products (1)
ncpfs/ncpfs 2.2.6
Published Mar 02, 2010
Tracked Since Feb 18, 2026