PT-2006-2651 · Linux · Util-Vserver
Dearaujo
·
Published
2006-04-06
·
Updated
2008-09-05
·
CVE-2006-1656
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
util-vserver version 0.30.209
Description:
The issue allows local users to potentially execute commands as root when the suexec userid parameter is invalid and non-numeric. This could lead to the execution of dangerous commands with elevated privileges.
Recommendations:
For util-vserver version 0.30.209, ensure that the suexec userid parameter is properly validated to prevent the execution of commands as root with invalid or non-numeric user IDs. As a temporary workaround, consider restricting the use of the suexec feature until a proper fix is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Util-Vserver