CVE-2006-2194
published 2006-07-05CVE-2006-2194: The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain…
PriorityP426high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.40%
32.6th percentile
The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ppp | < ppp 2.4.4rel-1 (bookworm) | ppp 2.4.4rel-1 (bookworm) |
| point-to-point_protocol_project | point-to-point_protocol | <= 2.4.4 | — |
| samba | ppp | >= 0 < 2.4.4rel-1 | 2.4.4rel-1 |
| samba | ppp | >= 0 < 2.4.4rel-1 | 2.4.4rel-1 |
| samba | ppp | >= 0 < 2.4.4rel-1 | 2.4.4rel-1 |
| samba | ppp | >= 0 < 2.4.4rel-1 | 2.4.4rel-1 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2MEDIUM
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ppp vulnerability
vendor_ubuntu·2006-07-06
CVE-2006-2194 ppp vulnerability
Title: ppp vulnerability
Summary: ppp vulnerability
Marcus Meissner discovered that the winbind plugin of pppd does not
check the result of the setuid() call. On systems that configure PAM
limits for the maximum number of user processes and enable the winbind
plugin, a local attacker could exploit this to execute the winbind
NTLM authentication helper as root. Depending on the local winbind
configuration, this could potentially lead to privilege escalation.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2006-2194: ppp - The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return c...
vendor_debian·2006·CVSS 7.2
CVE-2006-2194 [HIGH] CVE-2006-2194: ppp - The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return c...
The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.
Scope: local
bookworm: resolved (fixed in 2.4.4rel-1)
bullseye: resolved (fixed in 2.4.4rel-1)
forky: resolved (fixed in 2.4.4rel-1)
sid: resolved (fixed in 2.4.4rel-1)
trixie: resolved (fixed in 2.4.4rel-1)
Red Hat
CVE-2006-2194: The winbind plugin in pppd for ppp 2
vendor_redhat·CVSS 7.2
CVE-2006-2194 [HIGH] CVE-2006-2194: The winbind plugin in pppd for ppp 2
The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.
Statement: Not vulnerable. The winbind plugin is not shipped with Red Hat Enterprise Linux 2.1, 3, or 4.
GHSA
GHSA-wh53-gc5h-qjj9: The winbind plugin in pppd for ppp 2
ghsa_unreviewed·2022-05-01
CVE-2006-2194 [HIGH] GHSA-wh53-gc5h-qjj9: The winbind plugin in pppd for ppp 2
The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.
OSV
CVE-2006-2194: The winbind plugin in pppd for ppp 2
osv·2006-07-05·CVSS 7.2
CVE-2006-2194 [HIGH] CVE-2006-2194: The winbind plugin in pppd for ppp 2
The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/20963http://secunia.com/advisories/20967http://secunia.com/advisories/20987http://secunia.com/advisories/20996http://www.debian.org/security/2006/dsa-1106http://www.mandriva.com/security/advisories?name=MDKSA-2006:119http://www.osvdb.org/26994http://www.securityfocus.com/bid/18849http://www.ubuntu.com/usn/usn-310-1http://secunia.com/advisories/20963http://secunia.com/advisories/20967http://secunia.com/advisories/20987http://secunia.com/advisories/20996http://www.debian.org/security/2006/dsa-1106http://www.mandriva.com/security/advisories?name=MDKSA-2006:119http://www.osvdb.org/26994http://www.securityfocus.com/bid/18849http://www.ubuntu.com/usn/usn-310-1
2006-07-05
Published