CVE-2006-2654
Last modified
CVE-2006-2654 is a vulnerability of currently unknown severity. Directory traversal vulnerability in smbfs smbfs on FreeBSD 4.10 up to 6.1 allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences. NOTE: this is similar to CVE-2006-1864, but this is a different implementation of smbfs, so it has a different CVE identifier.. EPSS estimates a 2.70% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in smbfs smbfs on FreeBSD 4.10 up to 6.1 allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences. NOTE: this is similar to CVE-2006-1864, but this is a different implementation of smbfs, so it has a different CVE identifier.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 5.0 |
| Freebsd | Freebsd | 5.1 |
| Freebsd | Freebsd | 5.2 |
| Freebsd | Freebsd | 5.2.1 |
| Freebsd | Freebsd | 5.3 |
| Freebsd | Freebsd | 5.4 |
| Freebsd | Freebsd | 6.0 |
References
- http://secunia.com/advisories/20390Vendor Advisory
- http://secunia.com/advisories/20390Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-2654?
How severe is CVE-2006-2654?
How do I fix CVE-2006-2654?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-2648Cross-site scripting (XSS) vulnerability in perform_search.a…
- CVE-2006-2649Multiple cross-site scripting (XSS) vulnerabilities in (a) s…
- CVE-2006-2650SQL injection vulnerability in cosmicshop/search.php in Cosm…
- CVE-2006-2651Cross-site scripting (XSS) vulnerability in index.php in Vac…
- CVE-2006-2652Cross-site scripting (XSS) vulnerability in WikiNi 0.4.2 and…
- CVE-2006-2653Cross-site scripting (XSS) vulnerability in login_error.shtm…
- CVE-2006-2655The build process for ypserv in FreeBSD 5.3 up to 6.1 accide…
- CVE-2006-2656Stack-based buffer overflow in the tiffsplit command in libt…
- CVE-2006-2657Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2006-2658Directory traversal vulnerability in the xsp component in mo…
- CVE-2006-2659libs/comverp.c in Courier MTA before 0.53.2 allows attackers…
- CVE-2006-2660Buffer consumption vulnerability in the tempnam function in …
Are you affected by CVE-2006-2654?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
