7.2

CVE-2006-3378

passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.

Data is provided by the National Vulnerability Database (NVD)
UbuntuUbuntu Linux Version5.04 Editionamd64
UbuntuUbuntu Linux Version5.04 Editioni386
UbuntuUbuntu Linux Version5.04 Editionpowerpc
UbuntuUbuntu Linux Version5.10 Editionamd64
UbuntuUbuntu Linux Version5.10 Editioni386
UbuntuUbuntu Linux Version5.10 Editionpowerpc
UbuntuUbuntu Linux Version5.10 Editionsparc
UbuntuUbuntu Linux Version6.06_lts Editionamd64
UbuntuUbuntu Linux Version6.06_lts Editioni386
UbuntuUbuntu Linux Version6.06_lts Editionpowerpc
UbuntuUbuntu Linux Version6.06_lts Editionsparc
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.142
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C