{"api_version":"1","generated_at":"2026-07-23T05:00:58+00:00","cve":"CVE-2005-0666","urls":{"html":"https://cve.report/CVE-2005-0666","api":"https://cve.report/api/cve/CVE-2005-0666.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-0666","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-0666"},"summary":{"title":"CVE-2005-0666","description":"Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local users and possibly remote attackers to bypass intended access restrictions and execute arbitrary code.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-05-02 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/392348","name":"http://www.securityfocus.com/archive/1/392348","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/14489","name":"http://secunia.com/advisories/14489","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - PaX VMA Mirroring Unmapping Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/12729","name":"http://www.securityfocus.com/bid/12729","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"PaX VMA Mirroring Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-0666","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-0666","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"666","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"the_pax_team","cpe5":"pax_linux","cpe6":"2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"666","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"the_pax_team","cpe5":"pax_linux","cpe6":"2.4.20","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"666","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"the_pax_team","cpe5":"pax_linux","cpe6":"2.4.21","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"666","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"the_pax_team","cpe5":"pax_linux","cpe6":"2.4.22","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"666","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"the_pax_team","cpe5":"pax_linux","cpe6":"2.4.23","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"666","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"the_pax_team","cpe5":"pax_linux","cpe6":"2.4.24","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"666","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"the_pax_team","cpe5":"pax_linux","cpe6":"2.4.25","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"666","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"the_pax_team","cpe5":"pax_linux","cpe6":"2.4.26","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"666","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"the_pax_team","cpe5":"pax_linux","cpe6":"2.4.27","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"666","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"the_pax_team","cpe5":"pax_linux","cpe6":"2.4.28","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"666","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"the_pax_team","cpe5":"pax_linux","cpe6":"2.6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:21:06.458Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"12729","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/12729"},{"name":"20050305 PaX privilege elevation security bug","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/392348"},{"name":"14489","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/14489"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local users and possibly remote attackers to bypass intended access restrictions and execute arbitrary code."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-03-07T05:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"12729","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/12729"},{"name":"20050305 PaX privilege elevation security bug","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/392348"},{"name":"14489","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/14489"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-0666","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local users and possibly remote attackers to bypass intended access restrictions and execute arbitrary code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"12729","refsource":"BID","url":"http://www.securityfocus.com/bid/12729"},{"name":"20050305 PaX privilege elevation security bug","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/392348"},{"name":"14489","refsource":"SECUNIA","url":"http://secunia.com/advisories/14489"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-0666","datePublished":"2005-03-07T05:00:00.000Z","dateReserved":"2005-03-07T00:00:00.000Z","dateUpdated":"2024-09-16T23:11:03.610Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-02 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:the_pax_team:pax_linux:2.2:*:*:*:*:*:*:*","matchCriteriaId":"F9954840-C7F2-4395-AC59-10B2C21246C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:the_pax_team:pax_linux:2.4.20:*:*:*:*:*:*:*","matchCriteriaId":"16B22449-0C0C-45B3-9D7F-A778E179F57E"},{"vulnerable":true,"criteria":"cpe:2.3:a:the_pax_team:pax_linux:2.4.21:*:*:*:*:*:*:*","matchCriteriaId":"1BDD01E4-A51C-4725-BA3A-F15A3CB40EC2"},{"vulnerable":true,"criteria":"cpe:2.3:a:the_pax_team:pax_linux:2.4.22:*:*:*:*:*:*:*","matchCriteriaId":"8FE17A36-1AA8-4CE2-92CD-3FD4EA7A2A3E"},{"vulnerable":true,"criteria":"cpe:2.3:a:the_pax_team:pax_linux:2.4.23:*:*:*:*:*:*:*","matchCriteriaId":"EC1377A5-B59B-4678-9F46-7698CD0807A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:the_pax_team:pax_linux:2.4.24:*:*:*:*:*:*:*","matchCriteriaId":"7EA43A4E-99F4-4FE6-866B-D279D261AD0A"},{"vulnerable":true,"criteria":"cpe:2.3:a:the_pax_team:pax_linux:2.4.25:*:*:*:*:*:*:*","matchCriteriaId":"E954A75E-28D5-4C39-9AA8-6541B849C115"},{"vulnerable":true,"criteria":"cpe:2.3:a:the_pax_team:pax_linux:2.4.26:*:*:*:*:*:*:*","matchCriteriaId":"6805F737-983F-4E16-A2E5-3917AAD73E9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:the_pax_team:pax_linux:2.4.27:*:*:*:*:*:*:*","matchCriteriaId":"78D07EE2-488C-42CF-AF1F-404F26ABD4B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:the_pax_team:pax_linux:2.4.28:*:*:*:*:*:*:*","matchCriteriaId":"4E68615C-5B26-47D8-A7EF-5732E803CA83"},{"vulnerable":true,"criteria":"cpe:2.3:a:the_pax_team:pax_linux:2.6.5:*:*:*:*:*:*:*","matchCriteriaId":"83CE3B1E-D4CB-4829-B6B8-080BA6116FA5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"666","Ordinal":"1","Title":"CVE-2005-0666","CVE":"CVE-2005-0666","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"666","Ordinal":"1","NoteData":"Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local users and possibly remote attackers to bypass intended access restrictions and execute arbitrary code.","Type":"Description","Title":"CVE-2005-0666"},{"CveYear":"2005","CveId":"666","Ordinal":"2","NoteData":"2005-03-07","Type":"Other","Title":"Published"}]}}}