Vulnerability CVE-2006-2916


Published: 2006-06-15   Modified: 2012-02-12

Description:
artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.

Type:

CWE-Other

CVSS2 => (AV:L/AC:H/Au:S/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6/10
10/10
1.5/10
Exploit range
Attack complexity
Authentication
Local
High
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
KDE -> ARTS 

 References:
http://dot.kde.org/1150310128/
http://mail.gnome.org/archives/beast/2006-December/msg00025.html
http://security.gentoo.org/glsa/glsa-200704-22.xml
http://securitytracker.com/id?1016298
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.468256
http://www.gentoo.org/security/en/glsa/glsa-200606-22.xml
http://www.kde.org/info/security/advisory-20060614-2.txt
http://www.mandriva.com/security/advisories?name=MDKSA-2006:107
http://www.novell.com/linux/security/advisories/2006_38_security.html
http://www.securityfocus.com/archive/1/437362/100/0/threaded
http://www.securityfocus.com/bid/18429
http://www.securityfocus.com/bid/23697
http://www.vupen.com/english/advisories/2006/2357
http://www.vupen.com/english/advisories/2007/0409
https://exchange.xforce.ibmcloud.com/vulnerabilities/27221

Copyright 2024, cxsecurity.com

 

Back to Top