CVE-2006-4316
Summary
| CVE | CVE-2006-4316 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-23 22:04:00 UTC |
| Updated | 2017-07-20 01:33:00 UTC |
| Description | SSH Tectia Management Agent 2.1.2 allows local users to gain root privileges by running a program called sshd, which is obtained from a process listing when the "Restart" action is selected from the Management server GUI, which causes the agent to locate the pathname of the user's program and restart it with root privileges. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ssh | Tectia Manager | 1.2 | All | All | All |
| Application | Ssh | Tectia Manager | 1.3 | All | All | All |
| Application | Ssh | Tectia Manager | 1.4 | All | All | All |
| Application | Ssh | Tectia Manager | 2.0 | All | All | All |
| Application | Ssh | Tectia Manager | 2.1.2 | All | All | All |
| Application | Ssh | Tectia Manager | 1.2 | All | All | All |
| Application | Ssh | Tectia Manager | 1.3 | All | All | All |
| Application | Ssh | Tectia Manager | 1.4 | All | All | All |
| Application | Ssh | Tectia Manager | 2.0 | All | All | All |
| Application | Ssh | Tectia Manager | 2.1.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SSH Tectia Management Agent Privilege Escalation - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| SSH Tectia Manager Agent Process Local Privilege Escalation Vulnerability | BID | www.securityfocus.com | |
| 28159 | OSVDB | www.osvdb.org | |
| SecurityTracker.com Archives - SSH Tectia Manager Process Restart Flaw May Let Local Users Gain Elevated Privileges | SECTRACK | securitytracker.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SSH - Company - News | CONFIRM | www.ssh.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.