CVE Vulnerabilities

CVE-2006-3378

Published: Jul 06, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.

Affected Software

Name Vendor Start Version End Version
Ubuntu_linux Ubuntu 5.04 (including) 5.04 (including)
Ubuntu_linux Ubuntu 5.10 (including) 5.10 (including)
Ubuntu_linux Ubuntu 6.06_lts (including) 6.06_lts (including)
Shadow Ubuntu dapper *
Shadow Ubuntu devel *
Shadow Ubuntu edgy *
Shadow Ubuntu feisty *

References