CVE-2006-2916
Last modified
CVE-2006-2916 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kde | Arts | 1.0 |
| Kde | Arts | 1.2 |
References
- http://dot.kde.org/1150310128/Not Applicable
- http://secunia.com/advisories/20677Broken Link, Vendor Advisory
- http://secunia.com/advisories/20786Broken Link, Vendor Advisory
- http://secunia.com/advisories/20827Broken Link, Vendor Advisory
- http://secunia.com/advisories/20868Broken Link, Vendor Advisory
- http://secunia.com/advisories/20899Broken Link, Vendor Advisory
- http://secunia.com/advisories/25032Broken Link
- http://secunia.com/advisories/25059Broken Link
- http://security.gentoo.org/glsa/glsa-200704-22.xmlThird Party Advisory
- http://securitytracker.com/id?1016298Broken Link, Third Party Advisory, VDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.468256Mailing List, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200606-22.xmlThird Party Advisory
- http://www.kde.org/info/security/advisory-20060614-2.txtPatch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:107Third Party Advisory
- http://www.osvdb.org/26506Broken Link
- http://www.securityfocus.com/archive/1/437362/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/18429Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/23697Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27221Third Party Advisory, VDB Entry
- http://dot.kde.org/1150310128/Not Applicable
- http://secunia.com/advisories/20677Broken Link, Vendor Advisory
- http://secunia.com/advisories/20786Broken Link, Vendor Advisory
- http://secunia.com/advisories/20827Broken Link, Vendor Advisory
- http://secunia.com/advisories/20868Broken Link, Vendor Advisory
- http://secunia.com/advisories/20899Broken Link, Vendor Advisory
- http://secunia.com/advisories/25032Broken Link
- http://secunia.com/advisories/25059Broken Link
- http://security.gentoo.org/glsa/glsa-200704-22.xmlThird Party Advisory
- http://securitytracker.com/id?1016298Broken Link, Third Party Advisory, VDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.468256Mailing List, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200606-22.xmlThird Party Advisory
- http://www.kde.org/info/security/advisory-20060614-2.txtPatch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:107Third Party Advisory
- http://www.osvdb.org/26506Broken Link
- http://www.securityfocus.com/archive/1/437362/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/18429Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/23697Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27221Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-2916?
How severe is CVE-2006-2916?
How do I fix CVE-2006-2916?
Are you affected by CVE-2006-2916?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
