CVE-2006-3378
published 2006-07-06CVE-2006-3378: passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might…
PriorityP424high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.34%
26.5th percentile
passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | shadow | < shadow 1:4.0.14-1 (bookworm) | shadow 1:4.0.14-1 (bookworm) |
| shadow_project | shadow | >= 0 < 1:4.0.14-1 | 1:4.0.14-1 |
| shadow_project | shadow | >= 0 < 1:4.0.14-1 | 1:4.0.14-1 |
| shadow_project | shadow | >= 0 < 1:4.0.14-1 | 1:4.0.14-1 |
| shadow_project | shadow | >= 0 < 1:4.0.14-1 | 1:4.0.14-1 |
| ubuntu | ubuntu_linux | — | — |
| ubuntu | ubuntu_linux | — | — |
| ubuntu | ubuntu_linux | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-34pj-cg9w-gxv3: passwd command in shadow in Ubuntu 5
ghsa_unreviewed·2022-05-01
CVE-2006-3378 [HIGH] GHSA-34pj-cg9w-gxv3: passwd command in shadow in Ubuntu 5
passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.
OSV
CVE-2006-3378: passwd command in shadow in Ubuntu 5
osv·2006-07-06·CVSS 7.2
CVE-2006-3378 [HIGH] CVE-2006-3378: passwd command in shadow in Ubuntu 5
passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.
Ubuntu
shadow vulnerability
vendor_ubuntu·2006-07-06
CVE-2006-3378 shadow vulnerability
Title: shadow vulnerability
Summary: shadow vulnerability
Ilja van Sprundel discovered that passwd, when called with the -f, -g,
or -s option, did not check the result of the setuid() call. On
systems that configure PAM limits for the maximum number of user
processes, a local attacker could exploit this to execute chfn,
gpasswd, or chsh with root privileges.
This does not affect the default configuration of Ubuntu.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2006-3378: shadow - passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -...
vendor_debian·2006·CVSS 7.2
CVE-2006-3378 [HIGH] CVE-2006-3378: shadow - passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -...
passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.
Scope: local
bookworm: resolved (fixed in 1:4.0.14-1)
bullseye: resolved (fixed in 1:4.0.14-1)
forky: resolved (fixed in 1:4.0.14-1)
sid: resolved (fixed in 1:4.0.14-1)
trixie: resolved (fixed in 1:4.0.14-1)
Red Hat
CVE-2006-3378: passwd command in shadow in Ubuntu 5
vendor_redhat·CVSS 7.2
CVE-2006-3378 [HIGH] CVE-2006-3378: passwd command in shadow in Ubuntu 5
passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.
Statement: This issue affects the version of the passwd command from the shadow-utils package. Red Hat Enterprise Linux 2.1, 3, and 4 are not vulnerable to this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/20950http://secunia.com/advisories/20966http://secunia.com/advisories/21480http://www.debian.org/security/2006/dsa-1150http://www.osvdb.org/26995http://www.securityfocus.com/bid/18850http://www.ubuntu.com/usn/usn-308-1http://secunia.com/advisories/20950http://secunia.com/advisories/20966http://secunia.com/advisories/21480http://www.debian.org/security/2006/dsa-1150http://www.osvdb.org/26995http://www.securityfocus.com/bid/18850http://www.ubuntu.com/usn/usn-308-1
2006-07-06
Published