CVE
- Id
- 18711
- CVE No.
- CVE-2006-2607
- Status
- Candidate
- Description
- do_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits, as originally demonstrated by a program that exceeds the process limits as defined in /etc/security/limits.conf.
- Phase
- Assigned (20060525)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
163622 | 18711 | CVE-2006-2607 | BUGTRAQ:20060525 rPSA-2006-0082-1 vixie-cron | View |
163623 | 18711 | CVE-2006-2607 | URL:http://www.securityfocus.com/archive/1/archive/1/435033/100/0/threaded | View |
163624 | 18711 | CVE-2006-2607 | CONFIRM:http://bugs.gentoo.org/show_bug.cgi?id=134194 | View |
163625 | 18711 | CVE-2006-2607 | CONFIRM:https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178431 | View |
163626 | 18711 | CVE-2006-2607 | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2006-168.htm | View |
163627 | 18711 | CVE-2006-2607 | GENTOO:GLSA-200606-07 | View |
163628 | 18711 | CVE-2006-2607 | URL:http://security.gentoo.org/glsa/glsa-200606-07.xml | View |
163629 | 18711 | CVE-2006-2607 | REDHAT:RHSA-2006:0539 | View |
163630 | 18711 | CVE-2006-2607 | URL:http://www.redhat.com/support/errata/RHSA-2006-0539.html | View |
163631 | 18711 | CVE-2006-2607 | SUSE:SUSE-SA:2006:027 | View |
163632 | 18711 | CVE-2006-2607 | URL:http://www.novell.com/linux/security/advisories/2006-05-32.html | View |
163633 | 18711 | CVE-2006-2607 | UBUNTU:USN-778-1 | View |
163634 | 18711 | CVE-2006-2607 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-778-1 | View |
163635 | 18711 | CVE-2006-2607 | BID:18108 | View |
163636 | 18711 | CVE-2006-2607 | URL:http://www.securityfocus.com/bid/18108 | View |
163637 | 18711 | CVE-2006-2607 | OVAL:oval:org.mitre.oval:def:10213 | View |
163638 | 18711 | CVE-2006-2607 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10213 | View |
163639 | 18711 | CVE-2006-2607 | SECUNIA:35318 | View |
163640 | 18711 | CVE-2006-2607 | URL:http://secunia.com/advisories/35318 | View |
163641 | 18711 | CVE-2006-2607 | VUPEN:ADV-2006-2075 | View |
163642 | 18711 | CVE-2006-2607 | URL:http://www.vupen.com/english/advisories/2006/2075 | View |
163643 | 18711 | CVE-2006-2607 | SECTRACK:1016480 | View |
163644 | 18711 | CVE-2006-2607 | URL:http://securitytracker.com/id?1016480 | View |
163645 | 18711 | CVE-2006-2607 | SECUNIA:20380 | View |
163646 | 18711 | CVE-2006-2607 | URL:http://secunia.com/advisories/20380 | View |
163647 | 18711 | CVE-2006-2607 | SECUNIA:20388 | View |
163648 | 18711 | CVE-2006-2607 | URL:http://secunia.com/advisories/20388 | View |
163649 | 18711 | CVE-2006-2607 | SECUNIA:20616 | View |
163650 | 18711 | CVE-2006-2607 | URL:http://secunia.com/advisories/20616 | View |
163651 | 18711 | CVE-2006-2607 | SECUNIA:21032 | View |
163652 | 18711 | CVE-2006-2607 | URL:http://secunia.com/advisories/21032 | View |
163653 | 18711 | CVE-2006-2607 | SECUNIA:21702 | View |
163654 | 18711 | CVE-2006-2607 | URL:http://secunia.com/advisories/21702 | View |
163655 | 18711 | CVE-2006-2607 | XF:vixie-cron-docommand-gain-privilege(26691) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
61529 | JVNDB-2006-003795 | artmedic newsletter における任意のファイルを変更される脆弱性 | artmedic newsletter には、任意のファイルを変更される、および任意の PHP コードを実行される脆弱性が存在します。 | CVE-2006-2609 | 18711 | 5.1 | http://jvndb.jvn.jp/ja/contents/2006/JVNDB-2006-003795.html | View |