CVE Vulnerabilities

CVE-2006-3378

Published: Jul 06, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.

Affected Software

NameVendorStart VersionEnd Version
Ubuntu_linuxUbuntu5.04 (including)5.04 (including)
Ubuntu_linuxUbuntu5.10 (including)5.10 (including)
Ubuntu_linuxUbuntu6.06_lts (including)6.06_lts (including)
ShadowUbuntudapper*
ShadowUbuntudevel*
ShadowUbuntuedgy*
ShadowUbuntufeisty*

References