Linux · Util-Vserver · CVE-2006-1656
Name of the Vulnerable Software and Affected Versions:
util-vserver version 0.30.209
Description:
The issue allows local users to potentially execute commands as root when the suexec userid parameter is invalid and non-numeric. This could lead to the execution of dangerous commands with elevated privileges.
Recommendations:
For util-vserver version 0.30.209, ensure that the suexec userid parameter is properly validated to prevent the execution of commands as root with invalid or non-numeric user IDs. As a temporary workaround, consider restricting the use of the suexec feature until a proper fix is applied.