PT-2006-2299 · Freebsd · Freebsd

Published

2006-03-23

·

Updated

2017-07-20

·

CVE-2006-1283

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeBSD versions 4.10-RELEASE-p22 through 6.1-STABLE before 20060322
Description The issue allows local users to potentially gain root privileges by configuring OPIE access to the root account. This could be possible if a root shell is permitted by the configuration of the wheel group or sshd. The getlogin function is used to determine the invoking user account.
Recommendations For FreeBSD versions 4.10-RELEASE-p22 through 6.1-STABLE before 20060322, consider restricting access to the opiepasswd function to prevent local users from configuring OPIE access to the root account until a fix is applied. As a temporary workaround, review and restrict the configuration of the wheel group and sshd to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1283

Affected Products

Freebsd