Vulnerability Name: | CVE-2006-3378 (CCN-27754) | ||||||||
Assigned: | 2006-07-05 | ||||||||
Published: | 2006-07-05 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits. | ||||||||
CVSS v3 Severity: | 8.2 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-3378 Source: CCN Type: SA20950 shadow setuid Vulnerability Source: SECUNIA Type: UNKNOWN 20950 Source: SECUNIA Type: UNKNOWN 20966 Source: SECUNIA Type: UNKNOWN 21480 Source: DEBIAN Type: UNKNOWN DSA-1150 Source: DEBIAN Type: DSA-1150 shadow -- programming error Source: OSVDB Type: UNKNOWN 26995 Source: CCN Type: OSVDB ID: 26995 shadow setuid Failure Local Privilege Escalation Source: BID Type: UNKNOWN 18850 Source: CCN Type: BID-18850 Ubuntu Linux Passwd Potential Privilege Escalation Vulnerability Source: CCN Type: USN-308-1 shadow vulnerability Source: UBUNTU Type: UNKNOWN USN-308-1 Source: XF Type: UNKNOWN shadow-passwd-privilege-escalation(27754) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |