CVE-2006-3084

The (1) ftpd and (2) ksu programs in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which might allow local users to gain privileges by causing setuid to fail to drop privileges. NOTE: as of 20060808, it is not known whether an exploitable attack scenario exists for these issues.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:heimdal:heimdal:*:*:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.4:*:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:mit:kerberos_5:1.5:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-08-09 10:04

Updated : 2023-12-10 10:28


NVD link : CVE-2006-3084

Mitre link : CVE-2006-3084

CVE.ORG link : CVE-2006-3084


JSON object : View

Products Affected

mit

  • kerberos_5

heimdal

  • heimdal
CWE
CWE-264

Permissions, Privileges, and Access Controls