cbcvebase.
CVE-2006-1174
published 2006-05-28

CVE-2006-1174: useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new…

low3.7CVSS 3.1
AVLACHAuNCPIPAP
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianshadow< shadow 1:4.0.15-10 (bookworm)shadow 1:4.0.15-10 (bookworm)
debianshadow<= 4.0.7
debianshadow
debianshadow
debianshadow
debianshadow
debianshadow
debianshadow
debianshadow
shadow_projectshadow>= 0 < 1:4.0.15-101:4.0.15-10
shadow_projectshadow>= 0 < 1:4.0.15-101:4.0.15-10
shadow_projectshadow>= 0 < 1:4.0.15-101:4.0.15-10
shadow_projectshadow>= 0 < 1:4.0.15-101:4.0.15-10

CVSS provenance

nvd3.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
osv3.7LOW