CVE Vulnerabilities

CVE-2006-2607

Published: May 25, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

do_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits, as originally demonstrated by a program that exceeds the process limits as defined in /etc/security/limits.conf.

Affected Software

NameVendorStart VersionEnd Version
Vixie_cronPaul_vixie4.1 (including)4.1 (including)
Red Hat Enterprise Linux 4RedHatvixie-cron-4:4.1-44.EL4*
CronUbuntudapper*
CronUbuntudevel*
CronUbuntuedgy*
CronUbuntufeisty*
CronUbuntugutsy*
CronUbuntuhardy*
CronUbuntuintrepid*
CronUbuntujaunty*
CronUbuntuupstream*

References