ID | CVE-2006-3378 | ||||||
Sažetak | passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits. | ||||||
Reference | |||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:L/AC:L/Au:N/C:C/I:C/A:C | ||||||
Zadnje važnije ažuriranje | 05-09-2008 - 21:06 | ||||||
Objavljeno | 06-07-2006 - 20:05 |