PT-2006-2651 · Linux · Util-Vserver

Dearaujo

·

Published

2006-04-06

·

Updated

2008-09-05

·

CVE-2006-1656

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: util-vserver version 0.30.209
Description: The issue allows local users to potentially execute commands as root when the suexec userid parameter is invalid and non-numeric. This could lead to the execution of dangerous commands with elevated privileges.
Recommendations: For util-vserver version 0.30.209, ensure that the suexec userid parameter is properly validated to prevent the execution of commands as root with invalid or non-numeric user IDs. As a temporary workaround, consider restricting the use of the suexec feature until a proper fix is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1656

Affected Products

Util-Vserver