CVE-2006-1656
published 2006-04-06CVE-2006-1656: vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to…
PriorityP423high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.35%
27.5th percentile
vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vserver | util-vserver | <= 0.30.210 | — |
| vserver | util-vserver | — | — |
| vserver | util-vserver | >= 0 < 0.30.210-1 | 0.30.210-1 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xj9p-m2qr-5p2f: vserver in util-vserver 0
ghsa_unreviewed·2022-05-01
CVE-2006-1656 [HIGH] GHSA-xj9p-m2qr-5p2f: vserver in util-vserver 0
vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root.
OSV
CVE-2006-1656: vserver in util-vserver 0
osv·2006-04-06·CVSS 7.2
CVE-2006-1656 [HIGH] CVE-2006-1656: vserver in util-vserver 0
vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root.
No detection rules found.
No writeups or analysis indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=360438http://www.securityfocus.com/bid/17361https://savannah.nongnu.org/bugs/?func=detailitem&item_id=15996https://savannah.nongnu.org/patch/?func=detailitem&item_id=4966http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=360438http://www.securityfocus.com/bid/17361https://savannah.nongnu.org/bugs/?func=detailitem&item_id=15996https://savannah.nongnu.org/patch/?func=detailitem&item_id=4966
2006-04-06
Published