CVE-2006-2916
Last modified
CVE-2006-2916 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kde | Arts | 1.0 |
| Kde | Arts | 1.2 |
References
- http://dot.kde.org/1150310128/Not Applicable
- http://secunia.com/advisories/20677Broken Link, Vendor Advisory
- http://secunia.com/advisories/20786Broken Link, Vendor Advisory
- http://secunia.com/advisories/20827Broken Link, Vendor Advisory
- http://secunia.com/advisories/20868Broken Link, Vendor Advisory
- http://secunia.com/advisories/20899Broken Link, Vendor Advisory
- http://secunia.com/advisories/25032Broken Link
- http://secunia.com/advisories/25059Broken Link
- http://security.gentoo.org/glsa/glsa-200704-22.xmlThird Party Advisory
- http://securitytracker.com/id?1016298Broken Link, Third Party Advisory, VDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.468256Mailing List, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200606-22.xmlThird Party Advisory
- http://www.kde.org/info/security/advisory-20060614-2.txtPatch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:107Third Party Advisory
- http://www.osvdb.org/26506Broken Link
- http://www.securityfocus.com/archive/1/437362/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/18429Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/23697Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27221Third Party Advisory, VDB Entry
- http://dot.kde.org/1150310128/Not Applicable
- http://secunia.com/advisories/20677Broken Link, Vendor Advisory
- http://secunia.com/advisories/20786Broken Link, Vendor Advisory
- http://secunia.com/advisories/20827Broken Link, Vendor Advisory
- http://secunia.com/advisories/20868Broken Link, Vendor Advisory
- http://secunia.com/advisories/20899Broken Link, Vendor Advisory
- http://secunia.com/advisories/25032Broken Link
- http://secunia.com/advisories/25059Broken Link
- http://security.gentoo.org/glsa/glsa-200704-22.xmlThird Party Advisory
- http://securitytracker.com/id?1016298Broken Link, Third Party Advisory, VDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.468256Mailing List, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200606-22.xmlThird Party Advisory
- http://www.kde.org/info/security/advisory-20060614-2.txtPatch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:107Third Party Advisory
- http://www.osvdb.org/26506Broken Link
- http://www.securityfocus.com/archive/1/437362/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/18429Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/23697Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27221Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-2916?
How severe is CVE-2006-2916?
How do I fix CVE-2006-2916?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-2910Buffer overflow in jetAudio 6.2.6.8330 (Basic), and possibly…
- CVE-2006-2911SQL injection vulnerability in controlpanel/index.php in CMS…
- CVE-2006-2912Multiple SQL injection vulnerabilities in SelectaPix 1.31 al…
- CVE-2006-2913Cross-site scripting (XSS) vulnerability in SelectaPix 1.31 …
- CVE-2006-2914PHP remote file inclusion vulnerability in DeluxeBB 1.06 all…
- CVE-2006-2915Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allo…
- CVE-2006-2917Directory traversal vulnerability in the IMAP server in WinG…
- CVE-2006-2918The Lanap BotDetect APS.NET CAPTCHA component before 1.5.4.0…
- CVE-2006-2919Unspecified vulnerability in Microsoft NetMeeting 3.01 allow…
- CVE-2006-2920Sylpheed-Claws before 2.2.2 and Sylpheed before 2.2.6 allow …
- CVE-2006-2921PHP remote file inclusion vulnerability in cmpro_header.inc.…
- CVE-2006-2922Multiple PHP remote file inclusion vulnerabilities in Miraks…
Are you affected by CVE-2006-2916?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
