Vulnerability Name:

CVE-2006-1506 (CCN-43725)

Assigned:2006-03-29
Published:2006-03-29
Updated:2011-03-08
Summary:Unspecified vulnerability in rsh in Sun Microsystems Sun Grid Engine 5.3 before 20060327 and N1 Grid Engine 6.0 before 20060327 allows local users to gain root privileges.
This vulnerability affects Sun Microsystems, Sun Grid Engine 5.3 before 20060327 & N1 Grid Engine 6.0 before 20060327.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2006-1506

Source: CCN
Type: SunSource.net Web site
gridengine:Home

Source: CCN
Type: SECTRACK ID: 1015835
Sun Grid Engine `rsh` Bug Lets Local Users Obtain Root Privileges

Source: SECTRACK
Type: Patch
1015835

Source: CCN
Type: Sun Alert ID: 102268
Security Vulnerability in Sun Grid Engine/N1 Grid Engine rsh(1) Binary

Source: SUNALERT
Type: Patch
102268

Source: VUPEN
Type: UNKNOWN
ADV-2006-1155

Source: XF
Type: UNKNOWN
sge-n1grid-rsh-privilege-escalation(43725)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sun:grid_engine:5.3:*:*:*:*:*:*:*
  • OR cpe:/a:sun:n1_grid_engine:6.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:sun:grid_engine:5.3:*:*:*:*:*:*:*
  • OR cpe:/a:sun:n1_grid_engine:6.0:*:*:*:*:*:*:*
  • AND
  • cpe:/o:sun:solaris:7.0::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:7.0::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::x86:*:*:*:*:*
  • OR cpe:/o:sun:solaris:9::sparc:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sun grid engine 5.3
    sun n1 grid engine 6.0
    sun grid engine 5.3
    sun n1 grid engine 6.0
    sun solaris 7.0
    sun solaris 7.0
    sun solaris 8
    sun solaris 8
    sun solaris 9
    sun solaris 10
    sun solaris 10
    sun solaris 9