CVE
- Id
- 17278
- CVE No.
- CVE-2006-1174
- Status
- Candidate
- Description
- useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.
- Phase
- Assigned (20060312)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 142191 | 17278 | CVE-2006-1174 | BUGTRAQ:20070511 rPSA-2007-0096-1 shadow | View |
| 142192 | 17278 | CVE-2006-1174 | URL:http://www.securityfocus.com/archive/1/archive/1/468336/100/0/threaded | View |
| 142193 | 17278 | CVE-2006-1174 | FULLDISC:20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player | View |
| 142194 | 17278 | CVE-2006-1174 | URL:http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html | View |
| 142195 | 17278 | CVE-2006-1174 | CONFIRM:http://cvs.pld.org.pl/shadow/NEWS?rev=1.109 | View |
| 142196 | 17278 | CVE-2006-1174 | CONFIRM:https://issues.rpath.com/browse/RPL-1357 | View |
| 142197 | 17278 | CVE-2006-1174 | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2007-249.htm | View |
| 142198 | 17278 | CVE-2006-1174 | GENTOO:GLSA-200606-02 | View |
| 142199 | 17278 | CVE-2006-1174 | URL:http://www.gentoo.org/security/en/glsa/glsa-200606-02.xml | View |
| 142200 | 17278 | CVE-2006-1174 | MANDRIVA:MDKSA-2006:090 | View |
| 142201 | 17278 | CVE-2006-1174 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:090 | View |
| 142202 | 17278 | CVE-2006-1174 | REDHAT:RHSA-2007:0276 | View |
| 142203 | 17278 | CVE-2006-1174 | URL:http://www.redhat.com/support/errata/RHSA-2007-0276.html | View |
| 142204 | 17278 | CVE-2006-1174 | REDHAT:RHSA-2007:0431 | View |
| 142205 | 17278 | CVE-2006-1174 | URL:http://www.redhat.com/support/errata/RHSA-2007-0431.html | View |
| 142206 | 17278 | CVE-2006-1174 | SGI:20070602-01-P | View |
| 142207 | 17278 | CVE-2006-1174 | URL:ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc | View |
| 142208 | 17278 | CVE-2006-1174 | CERT-VN:VU#312692 | View |
| 142209 | 17278 | CVE-2006-1174 | URL:http://www.kb.cert.org/vuls/id/312692 | View |
| 142210 | 17278 | CVE-2006-1174 | BID:18111 | View |
| 142211 | 17278 | CVE-2006-1174 | URL:http://www.securityfocus.com/bid/18111 | View |
| 142212 | 17278 | CVE-2006-1174 | OVAL:oval:org.mitre.oval:def:10807 | View |
| 142213 | 17278 | CVE-2006-1174 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10807 | View |
| 142214 | 17278 | CVE-2006-1174 | VUPEN:ADV-2006-2006 | View |
| 142215 | 17278 | CVE-2006-1174 | URL:http://www.vupen.com/english/advisories/2006/2006 | View |
| 142216 | 17278 | CVE-2006-1174 | VUPEN:ADV-2007-3229 | View |
| 142217 | 17278 | CVE-2006-1174 | URL:http://www.vupen.com/english/advisories/2007/3229 | View |
| 142218 | 17278 | CVE-2006-1174 | SECTRACK:1018221 | View |
| 142219 | 17278 | CVE-2006-1174 | URL:http://www.securitytracker.com/id?1018221 | View |
| 142220 | 17278 | CVE-2006-1174 | SECUNIA:20370 | View |
| 142221 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/20370 | View |
| 142222 | 17278 | CVE-2006-1174 | SECUNIA:20506 | View |
| 142223 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/20506 | View |
| 142224 | 17278 | CVE-2006-1174 | SECUNIA:25098 | View |
| 142225 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/25098 | View |
| 142226 | 17278 | CVE-2006-1174 | SECUNIA:25267 | View |
| 142227 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/25267 | View |
| 142228 | 17278 | CVE-2006-1174 | SECUNIA:25629 | View |
| 142229 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/25629 | View |
| 142230 | 17278 | CVE-2006-1174 | SECUNIA:25894 | View |
| 142231 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/25894 | View |
| 142232 | 17278 | CVE-2006-1174 | SECUNIA:25896 | View |
| 142233 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/25896 | View |
| 142234 | 17278 | CVE-2006-1174 | SECUNIA:26909 | View |
| 142235 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/26909 | View |
| 142236 | 17278 | CVE-2006-1174 | SECUNIA:27706 | View |
| 142237 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/27706 | View |
| 142238 | 17278 | CVE-2006-1174 | XF:shadow-utils-useradd-file-permission(26958) | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 61643 | JVNDB-2006-003909 | eBay Enhanced Picture Services におけるバッファオーバーフローの脆弱性 | eBay Enhanced Picture Services には、バッファオーバーフローの脆弱性が存在します。 | CVE-2006-1176 | 17278 | 7.5 | http://jvndb.jvn.jp/ja/contents/2006/JVNDB-2006-003909.html | View |