CVE
- Id
- 17278
- CVE No.
- CVE-2006-1174
- Status
- Candidate
- Description
- useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.
- Phase
- Assigned (20060312)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
142191 | 17278 | CVE-2006-1174 | BUGTRAQ:20070511 rPSA-2007-0096-1 shadow | View |
142192 | 17278 | CVE-2006-1174 | URL:http://www.securityfocus.com/archive/1/archive/1/468336/100/0/threaded | View |
142193 | 17278 | CVE-2006-1174 | FULLDISC:20070920 VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player | View |
142194 | 17278 | CVE-2006-1174 | URL:http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html | View |
142195 | 17278 | CVE-2006-1174 | CONFIRM:http://cvs.pld.org.pl/shadow/NEWS?rev=1.109 | View |
142196 | 17278 | CVE-2006-1174 | CONFIRM:https://issues.rpath.com/browse/RPL-1357 | View |
142197 | 17278 | CVE-2006-1174 | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2007-249.htm | View |
142198 | 17278 | CVE-2006-1174 | GENTOO:GLSA-200606-02 | View |
142199 | 17278 | CVE-2006-1174 | URL:http://www.gentoo.org/security/en/glsa/glsa-200606-02.xml | View |
142200 | 17278 | CVE-2006-1174 | MANDRIVA:MDKSA-2006:090 | View |
142201 | 17278 | CVE-2006-1174 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:090 | View |
142202 | 17278 | CVE-2006-1174 | REDHAT:RHSA-2007:0276 | View |
142203 | 17278 | CVE-2006-1174 | URL:http://www.redhat.com/support/errata/RHSA-2007-0276.html | View |
142204 | 17278 | CVE-2006-1174 | REDHAT:RHSA-2007:0431 | View |
142205 | 17278 | CVE-2006-1174 | URL:http://www.redhat.com/support/errata/RHSA-2007-0431.html | View |
142206 | 17278 | CVE-2006-1174 | SGI:20070602-01-P | View |
142207 | 17278 | CVE-2006-1174 | URL:ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc | View |
142208 | 17278 | CVE-2006-1174 | CERT-VN:VU#312692 | View |
142209 | 17278 | CVE-2006-1174 | URL:http://www.kb.cert.org/vuls/id/312692 | View |
142210 | 17278 | CVE-2006-1174 | BID:18111 | View |
142211 | 17278 | CVE-2006-1174 | URL:http://www.securityfocus.com/bid/18111 | View |
142212 | 17278 | CVE-2006-1174 | OVAL:oval:org.mitre.oval:def:10807 | View |
142213 | 17278 | CVE-2006-1174 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10807 | View |
142214 | 17278 | CVE-2006-1174 | VUPEN:ADV-2006-2006 | View |
142215 | 17278 | CVE-2006-1174 | URL:http://www.vupen.com/english/advisories/2006/2006 | View |
142216 | 17278 | CVE-2006-1174 | VUPEN:ADV-2007-3229 | View |
142217 | 17278 | CVE-2006-1174 | URL:http://www.vupen.com/english/advisories/2007/3229 | View |
142218 | 17278 | CVE-2006-1174 | SECTRACK:1018221 | View |
142219 | 17278 | CVE-2006-1174 | URL:http://www.securitytracker.com/id?1018221 | View |
142220 | 17278 | CVE-2006-1174 | SECUNIA:20370 | View |
142221 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/20370 | View |
142222 | 17278 | CVE-2006-1174 | SECUNIA:20506 | View |
142223 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/20506 | View |
142224 | 17278 | CVE-2006-1174 | SECUNIA:25098 | View |
142225 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/25098 | View |
142226 | 17278 | CVE-2006-1174 | SECUNIA:25267 | View |
142227 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/25267 | View |
142228 | 17278 | CVE-2006-1174 | SECUNIA:25629 | View |
142229 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/25629 | View |
142230 | 17278 | CVE-2006-1174 | SECUNIA:25894 | View |
142231 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/25894 | View |
142232 | 17278 | CVE-2006-1174 | SECUNIA:25896 | View |
142233 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/25896 | View |
142234 | 17278 | CVE-2006-1174 | SECUNIA:26909 | View |
142235 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/26909 | View |
142236 | 17278 | CVE-2006-1174 | SECUNIA:27706 | View |
142237 | 17278 | CVE-2006-1174 | URL:http://secunia.com/advisories/27706 | View |
142238 | 17278 | CVE-2006-1174 | XF:shadow-utils-useradd-file-permission(26958) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
61643 | JVNDB-2006-003909 | eBay Enhanced Picture Services におけるバッファオーバーフローの脆弱性 | eBay Enhanced Picture Services には、バッファオーバーフローの脆弱性が存在します。 | CVE-2006-1176 | 17278 | 7.5 | http://jvndb.jvn.jp/ja/contents/2006/JVNDB-2006-003909.html | View |