Lucene search

K
cveDebianCVE-2006-2194
HistoryJul 05, 2006 - 6:05 p.m.

CVE-2006-2194

2006-07-0518:05:00
debian
web.nvd.nist.gov
37
cve-2006-2194
pppd
winbind
privilege escalation
setuid
nvd
security vulnerability

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

25.6%

The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.

Affected configurations

Nvd
Node
point-to-point_protocol_projectpoint-to-point_protocolRange≀2.4.4
VendorProductVersionCPE
point-to-point_protocol_projectpoint-to-point_protocol*cpe:2.3:a:point-to-point_protocol_project:point-to-point_protocol:*:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.6

Confidence

Low

EPSS

0.001

Percentile

25.6%