7.2

CVE-2006-3378

passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ubuntu ≫ Ubuntu Linux Version 5.04 Edition amd64
Ubuntu ≫ Ubuntu Linux Version 5.04 Edition i386
Ubuntu ≫ Ubuntu Linux Version 5.04 Edition powerpc
Ubuntu ≫ Ubuntu Linux Version 5.10 Edition amd64
Ubuntu ≫ Ubuntu Linux Version 5.10 Edition i386
Ubuntu ≫ Ubuntu Linux Version 5.10 Edition powerpc
Ubuntu ≫ Ubuntu Linux Version 5.10 Edition sparc
Ubuntu ≫ Ubuntu Linux Version 6.06_lts Edition amd64
Ubuntu ≫ Ubuntu Linux Version 6.06_lts Edition i386
Ubuntu ≫ Ubuntu Linux Version 6.06_lts Edition powerpc
Ubuntu ≫ Ubuntu Linux Version 6.06_lts Edition sparc
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.257
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/20950
http://secunia.com/advisories/20966
http://secunia.com/advisories/21480
http://www.debian.org/security/2006/dsa-1150
http://www.osvdb.org/26995
http://www.securityfocus.com/bid/18850
http://www.ubuntu.com/usn/usn-308-1