CVE-2006-3084
Summary
| CVE | CVE-2006-3084 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-09 10:04:00 UTC |
| Updated | 2020-01-21 15:45:00 UTC |
| Description | The (1) ftpd and (2) ksu programs in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which might allow local users to gain privileges by causing setuid to fail to drop privileges. NOTE: as of 20060808, it is not known whether an exploitable attack scenario exists for these issues. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Heimdal | Heimdal | All | All | All | All |
| Application | Mit | Kerberos 5 | 1.4 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.1 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.2 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.3 | All | All | All |
| Application | Mit | Kerberos 5 | 1.5 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.1 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.2 | All | All | All |
| Application | Mit | Kerberos 5 | 1.4.3 | All | All | All |
| Application | Mit | Kerberos 5 | 1.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 Not Found | FEDORA | fedoranews.org | |
| SecurityTracker.com Archives - Kerberos Application Flaws in Evaluating setuid/seteuid Calls May Let Local Users Gain Elevated Privileges | SECTRACK | securitytracker.com | |
| 27872 | OSVDB | www.osvdb.org | |
| Security Announcement | SUSE | www.novell.com | |
| Gentoo Linux Documentation -- MIT Kerberos 5: Multiple local privilege escalation vulnerabilities | GENTOO | www.gentoo.org | |
| 2006-08-08: multiple local privilege escalation vulnerabilities | CONFIRM | www.pdc.kth.se | |
| SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| Ubuntu update for krb5 - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| usn/usn-334-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Gentoo Linux Documentation -- Heimdal: Multiple local privilege escalation vulnerabilities | GENTOO | security.gentoo.org | |
| Secunia - Advisories - Heimdal setuid Security Issue | SECUNIA | secunia.com | Vendor Advisory |
| Gentoo update for heimdal - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Secunia - Advisories - Debian update for krb5 | SECUNIA | secunia.com | Vendor Advisory |
| Fedora Core 5 update for krb5 - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| web.mit.edu/Kerberos/advisories/MITKRB5-SA-2006-001-setuid.txt | CONFIRM | web.mit.edu | |
| MIT Kerberos 5 Multiple Local Privilege Escalation Vulnerabilities | BID | www.securityfocus.com | |
| ftp.pdc.kth.se/pub/heimdal/src/heimdal-0.7.2-setuid-patch.txt | CONFIRM | ftp.pdc.kth.se | |
| Gentoo update for mit-krb5 - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| US-CERT Vulnerability Note VU#401660 | CERT-VN | www.kb.cert.org | US Government Resource |
| Kerberos V5 setuid Security Issue - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail - OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1146-1 krb5 | DEBIAN | www.debian.org | |
| 27871 | OSVDB | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.