CVE Vulnerabilities

CVE-2006-3378

Published: Jul 06, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.

Affected Software

Name Vendor Start Version End Version
Ubuntu_linux Ubuntu 5.04 (including) 5.04 (including)
Ubuntu_linux Ubuntu 5.10 (including) 5.10 (including)
Ubuntu_linux Ubuntu 6.06_lts (including) 6.06_lts (including)
Shadow Ubuntu dapper *
Shadow Ubuntu devel *
Shadow Ubuntu edgy *
Shadow Ubuntu feisty *

References