CVE-2006-2916
Summary
| CVE | CVE-2006-2916 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-15 10:02:00 UTC |
| Updated | 2024-01-21 01:42:00 UTC |
| Description | artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges. |
Risk And Classification
Problem Types: CWE-273
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| aRts "artswrapper" Helper Application setuid Security Issue - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Gentoo update for beast - Advisories - Secunia | SECUNIA | secunia.com | |
| SUSE Updates for Multiple Packages - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Security Announcement | SUSE | www.novell.com | |
| SecurityTracker.com Archives - Artswrapper setuid() Failure Lets Local Users Gain Root Privileges | SECTRACK | securitytracker.com | |
| Beast Resource Limit Local Denial Of Service Vulnerability | BID | www.securityfocus.com | |
| Slackware update for arts - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail - OVH | VUPEN | www.vupen.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| The Slackware Linux Project: Slackware Security Advisories | SLACKWARE | slackware.com | |
| KDE ArtsWrapper Local Privilege Escalation Vulnerability | BID | www.securityfocus.com | Patch |
| Security Updates: Artswrapper and KDM | CONFIRM | dot.kde.org | Patch |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| BEAST/BSE "seteuid()" and "setreuid()" Security Issue - Advisories - Secunia | SECUNIA | secunia.com | |
| 26506 | OSVDB | www.osvdb.org | |
| ANNOUNCE: BEAST/BSE v0.7.1 | MLIST | mail.gnome.org | |
| www.kde.org/info/security/advisory-20060614-2.txt | CONFIRM | www.kde.org | Patch, Vendor Advisory |
| Mandriva update for arts - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| BEAST: Denial of Service — Gentoo Linux Documentation | GENTOO | security.gentoo.org | |
| Gentoo Linux Documentation -- aRts: Privilege escalation | GENTOO | www.gentoo.org | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| Secunia - Advisories - Gentoo update for aRts | SECUNIA | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2006-08-16 | Mark J Cox | Not vulnerable. We do not ship aRts as setuid root on Red Hat Enterprise Linux 2.1, 3, or 4. |
There are currently no legacy QID mappings associated with this CVE.