CVE
- Id
- 20551
- CVE No.
- CVE-2006-4447
- Status
- Candidate
- Description
- X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.
- Phase
- Assigned (20060829)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
192981 | 20551 | CVE-2006-4447 | MLIST:[xorg] 20060620 X.Org security advisory: setuid return value check problems | View |
192982 | 20551 | CVE-2006-4447 | URL:http://lists.freedesktop.org/archives/xorg/2006-June/016146.html | View |
192983 | 20551 | CVE-2006-4447 | MLIST:[beast] 20061228 ANNOUNCE: BEAST/BSE v0.7.1 | View |
192984 | 20551 | CVE-2006-4447 | URL:http://mail.gnome.org/archives/beast/2006-December/msg00025.html | View |
192985 | 20551 | CVE-2006-4447 | DEBIAN:DSA-1193 | View |
192986 | 20551 | CVE-2006-4447 | URL:http://www.debian.org/security/2006/dsa-1193 | View |
192987 | 20551 | CVE-2006-4447 | GENTOO:GLSA-200608-25 | View |
192988 | 20551 | CVE-2006-4447 | URL:http://security.gentoo.org/glsa/glsa-200608-25.xml | View |
192989 | 20551 | CVE-2006-4447 | GENTOO:GLSA-200704-22 | View |
192990 | 20551 | CVE-2006-4447 | URL:http://security.gentoo.org/glsa/glsa-200704-22.xml | View |
192991 | 20551 | CVE-2006-4447 | MANDRIVA:MDKSA-2006:160 | View |
192992 | 20551 | CVE-2006-4447 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2006:160 | View |
192993 | 20551 | CVE-2006-4447 | CERT-VN:VU#300368 | View |
192994 | 20551 | CVE-2006-4447 | URL:http://www.kb.cert.org/vuls/id/300368 | View |
192995 | 20551 | CVE-2006-4447 | BID:19742 | View |
192996 | 20551 | CVE-2006-4447 | URL:http://www.securityfocus.com/bid/19742 | View |
192997 | 20551 | CVE-2006-4447 | BID:23697 | View |
192998 | 20551 | CVE-2006-4447 | URL:http://www.securityfocus.com/bid/23697 | View |
192999 | 20551 | CVE-2006-4447 | VUPEN:ADV-2006-3409 | View |
193000 | 20551 | CVE-2006-4447 | URL:http://www.vupen.com/english/advisories/2006/3409 | View |
193001 | 20551 | CVE-2006-4447 | VUPEN:ADV-2007-0409 | View |
193002 | 20551 | CVE-2006-4447 | URL:http://www.vupen.com/english/advisories/2007/0409 | View |
193003 | 20551 | CVE-2006-4447 | SECUNIA:21650 | View |
193004 | 20551 | CVE-2006-4447 | URL:http://secunia.com/advisories/21650 | View |
193005 | 20551 | CVE-2006-4447 | SECUNIA:21660 | View |
193006 | 20551 | CVE-2006-4447 | URL:http://secunia.com/advisories/21660 | View |
193007 | 20551 | CVE-2006-4447 | SECUNIA:21693 | View |
193008 | 20551 | CVE-2006-4447 | URL:http://secunia.com/advisories/21693 | View |
193009 | 20551 | CVE-2006-4447 | SECUNIA:22332 | View |
193010 | 20551 | CVE-2006-4447 | URL:http://secunia.com/advisories/22332 | View |
193011 | 20551 | CVE-2006-4447 | SECUNIA:25032 | View |
193012 | 20551 | CVE-2006-4447 | URL:http://secunia.com/advisories/25032 | View |
193013 | 20551 | CVE-2006-4447 | SECUNIA:25059 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
59746 | JVNDB-2006-002012 | MyBB の attachment.php におけるクロスサイトスクリプティングの脆弱性 | MyBulletinBoard (MyBB) の attachment.php には、クロスサイトスクリプティングの脆弱性が存在します。 | CVE-2006-4449 | 20551 | 5.1 | http://jvndb.jvn.jp/ja/contents/2006/JVNDB-2006-002012.html | View |