7.2

CVE-2006-3378

passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
UbuntuUbuntu Linux Version5.04 Editionamd64
UbuntuUbuntu Linux Version5.04 Editioni386
UbuntuUbuntu Linux Version5.04 Editionpowerpc
UbuntuUbuntu Linux Version5.10 Editionamd64
UbuntuUbuntu Linux Version5.10 Editioni386
UbuntuUbuntu Linux Version5.10 Editionpowerpc
UbuntuUbuntu Linux Version5.10 Editionsparc
UbuntuUbuntu Linux Version6.06_lts Editionamd64
UbuntuUbuntu Linux Version6.06_lts Editioni386
UbuntuUbuntu Linux Version6.06_lts Editionpowerpc
UbuntuUbuntu Linux Version6.06_lts Editionsparc
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.142
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C