CVE-2006-1174
published 2006-05-28CVE-2006-1174: useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new…
PriorityP48low3.7CVSS 2.0
AVLACHAuNCPIPAP
EPSS
0.44%
36.1th percentile
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | shadow | < shadow 1:4.0.15-10 (bookworm) | shadow 1:4.0.15-10 (bookworm) |
| debian | shadow | <= 4.0.7 | — |
| debian | shadow | — | — |
| debian | shadow | — | — |
| debian | shadow | — | — |
| debian | shadow | — | — |
| debian | shadow | — | — |
| debian | shadow | — | — |
| debian | shadow | — | — |
| shadow_project | shadow | >= 0 < 1:4.0.15-10 | 1:4.0.15-10 |
| shadow_project | shadow | >= 0 < 1:4.0.15-10 | 1:4.0.15-10 |
| shadow_project | shadow | >= 0 < 1:4.0.15-10 | 1:4.0.15-10 |
| shadow_project | shadow | >= 0 < 1:4.0.15-10 | 1:4.0.15-10 |
CVSS provenance
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
osv3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2fgw-2v2m-w7mc: useradd in shadow-utils before 4
ghsa_unreviewed·2022-05-03
CVE-2006-1174 [LOW] GHSA-2fgw-2v2m-w7mc: useradd in shadow-utils before 4
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.
OSV
CVE-2006-1174: useradd in shadow-utils before 4
osv·2006-05-28·CVSS 3.7
CVE-2006-1174 [LOW] CVE-2006-1174: useradd in shadow-utils before 4
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.
Debian
CVE-2006-1174: shadow - useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, ...
vendor_debian·2006·CVSS 3.7
CVE-2006-1174 [LOW] CVE-2006-1174: shadow - useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, ...
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.
Scope: local
bookworm: resolved (fixed in 1:4.0.15-10)
bullseye: resolved (fixed in 1:4.0.15-10)
forky: resolved (fixed in 1:4.0.15-10)
sid: resolved (fixed in 1:4.0.15-10)
trixie: resolved (fixed in 1:4.0.15-10)
Red Hat
security flaw
vendor_redhat·2005-02-23·CVSS 3.7
CVE-2006-1174 [LOW] security flaw
security flaw
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.
Statement: Red Hat is aware of this issue and is tracking it via the following bugs:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=193053
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=229194
The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here:
http://www.redhat.com/security/updates/classification/
The risks associated with fixing t
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-1174 security flaw
bugzilla·2018-08-16·CVSS 3.7
CVE-2006-1174 [LOW] CVE-2006-1174 security flaw
CVE-2006-1174 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.
---
Statement:
Red Hat is aware of this issue and is tracking it via the following bugs:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=193053
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=229194
The Red Hat Security Response Team has rated this issue as having low security impact, a futu
Bugzilla
CVE-2006-1174 shadow-utils mailbox creation race condition
bugzilla·2007-02-19·CVSS 3.7
CVE-2006-1174 [LOW] CVE-2006-1174 shadow-utils mailbox creation race condition
CVE-2006-1174 shadow-utils mailbox creation race condition
Clone for rhel3/2.1
+++ This bug was initially created as a clone of Bug #193053 +++
shadow-utils mailbox creation race condition
CERT reported an issue with the way shadow-utils' useradd program
creates the users mail spool file. The file is intially created
improperly which gives it random permissions, owned by root for a
short period of time. It may be possible for a local attacker to get
very lucky and acquire write permissions to a world writable SUID
file.
The upstream fix is here:
http://cvs.pld.org.pl/shadow/src/useradd.c?r1=1.50&r2=1.51
When we patch our packages, we may want to check the return value of
the the fchown and fchmod calls.
This issue also affects RHEL3
This issue also affects RHEL2.1
Discussion:
fix
Bugzilla
CVE-2006-1174 shadow-utils mailbox creation race condition
bugzilla·2006-05-24·CVSS 3.7
CVE-2006-1174 [LOW] CVE-2006-1174 shadow-utils mailbox creation race condition
CVE-2006-1174 shadow-utils mailbox creation race condition
shadow-utils mailbox creation race condition
CERT reported an issue with the way shadow-utils' useradd program
creates the users mail spool file. The file is intially created
improperly which gives it random permissions, owned by root for a
short period of time. It may be possible for a local attacker to get
very lucky and acquire write permissions to a world writable SUID
file.
The upstream fix is here:
http://cvs.pld.org.pl/shadow/src/useradd.c?r1=1.50&r2=1.51
When we patch our packages, we may want to check the return value of
the the fchown and fchmod calls.
This issue also affects RHEL3
This issue also affects RHEL2.1
Discussion:
Created attachment 129979
"#useradd foo" strace output
I patched shadow-utils-4.0.3 from
ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.aschttp://cvs.pld.org.pl/shadow/NEWS?rev=1.109http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlhttp://secunia.com/advisories/20370http://secunia.com/advisories/20506http://secunia.com/advisories/25098http://secunia.com/advisories/25267http://secunia.com/advisories/25629http://secunia.com/advisories/25894http://secunia.com/advisories/25896http://secunia.com/advisories/26909http://secunia.com/advisories/27706http://support.avaya.com/elmodocs2/security/ASA-2007-249.htmhttp://www.gentoo.org/security/en/glsa/glsa-200606-02.xmlhttp://www.kb.cert.org/vuls/id/312692http://www.mandriva.com/security/advisories?name=MDKSA-2006:090http://www.redhat.com/support/errata/RHSA-2007-0276.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0431.htmlhttp://www.securityfocus.com/archive/1/468336/100/0/threadedhttp://www.securityfocus.com/bid/18111http://www.securitytracker.com/id?1018221http://www.vupen.com/english/advisories/2006/2006http://www.vupen.com/english/advisories/2007/3229https://exchange.xforce.ibmcloud.com/vulnerabilities/26958https://issues.rpath.com/browse/RPL-1357https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10807ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.aschttp://cvs.pld.org.pl/shadow/NEWS?rev=1.109http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlhttp://secunia.com/advisories/20370http://secunia.com/advisories/20506http://secunia.com/advisories/25098http://secunia.com/advisories/25267http://secunia.com/advisories/25629http://secunia.com/advisories/25894http://secunia.com/advisories/25896http://secunia.com/advisories/26909http://secunia.com/advisories/27706http://support.avaya.com/elmodocs2/security/ASA-2007-249.htmhttp://www.gentoo.org/security/en/glsa/glsa-200606-02.xmlhttp://www.kb.cert.org/vuls/id/312692http://www.mandriva.com/security/advisories?name=MDKSA-2006:090http://www.redhat.com/support/errata/RHSA-2007-0276.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0431.htmlhttp://www.securityfocus.com/archive/1/468336/100/0/threadedhttp://www.securityfocus.com/bid/18111http://www.securitytracker.com/id?1018221http://www.vupen.com/english/advisories/2006/2006http://www.vupen.com/english/advisories/2007/3229https://exchange.xforce.ibmcloud.com/vulnerabilities/26958https://issues.rpath.com/browse/RPL-1357https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10807
2006-05-28
Published