Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2006-3083
Description:The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion.
Test IDs: 1.3.6.1.4.1.25623.1.0.57242   1.3.6.1.4.1.25623.1.0.62299   1.3.6.1.4.1.25623.1.0.57251  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2006-3083
BugTraq ID: 19427
http://www.securityfocus.com/bid/19427
Bugtraq: 20060808 MITKRB-SA-2006-001: multiple local privilege escalation vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/442599/100/0/threaded
Bugtraq: 20060816 UPDATED: MITKRB5-SA-2006-001: multiple local privilege escalation vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/443498/100/100/threaded
CERT/CC vulnerability note: VU#580124
http://www.kb.cert.org/vuls/id/580124
Debian Security Information: DSA-1146 (Google Search)
http://www.debian.org/security/2006/dsa-1146
http://www.gentoo.org/security/en/glsa/glsa-200608-15.xml
http://security.gentoo.org/glsa/glsa-200608-21.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:139
http://www.osvdb.org/27869
http://www.osvdb.org/27870
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9515
RedHat Security Advisories: RHSA-2006:0612
http://www.redhat.com/support/errata/RHSA-2006-0612.html
http://securitytracker.com/id?1016664
http://secunia.com/advisories/21402
http://secunia.com/advisories/21423
http://secunia.com/advisories/21436
http://secunia.com/advisories/21439
http://secunia.com/advisories/21441
http://secunia.com/advisories/21456
http://secunia.com/advisories/21461
http://secunia.com/advisories/21467
http://secunia.com/advisories/21527
http://secunia.com/advisories/21613
http://secunia.com/advisories/21847
http://secunia.com/advisories/22291
SuSE Security Announcement: SUSE-SR:2006:020 (Google Search)
http://www.novell.com/linux/security/advisories/2006_20_sr.html
SuSE Security Announcement: SUSE-SR:2006:022 (Google Search)
http://www.novell.com/linux/security/advisories/2006_22_sr.html
http://www.ubuntu.com/usn/usn-334-1
http://www.vupen.com/english/advisories/2006/3225




© 1998-2025 E-Soft Inc. All rights reserved.