CVE-2006-4447
published 2006-08-30CVE-2006-4447: X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when…
PriorityP426high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.43%
35.2th percentile
X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libx11 | < libx11 2:1.0.0-7 (bookworm) | libx11 2:1.0.0-7 (bookworm) |
| debian | xdm | < libx11 2:1.0.0-7 (bookworm) | libx11 2:1.0.0-7 (bookworm) |
| debian | xorg-server | < libx11 2:1.0.0-7 (bookworm) | libx11 2:1.0.0-7 (bookworm) |
| debian | xterm | < libx11 2:1.0.0-7 (bookworm) | libx11 2:1.0.0-7 (bookworm) |
| debian | xtrans | < libx11 2:1.0.0-7 (bookworm) | libx11 2:1.0.0-7 (bookworm) |
| x.org | emu-linux-x87-xlibs | — | — |
| x.org | libx11 | >= 0 < 2:1.0.0-7 | 2:1.0.0-7 |
| x.org | libx11 | >= 0 < 2:1.0.0-7 | 2:1.0.0-7 |
| x.org | libx11 | >= 0 < 2:1.0.0-7 | 2:1.0.0-7 |
| x.org | libx11 | >= 0 < 2:1.0.0-7 | 2:1.0.0-7 |
| x.org | x11r6 | — | — |
| x.org | x11r6 | — | — |
| x.org | x11r6 | — | — |
| x.org | x11r6 | — | — |
| x.org | x11r7 | — | — |
| x.org | x11r7 | — | — |
| x.org | x11r7 | — | — |
| x.org | xdm | — | — |
| x.org | xdm | >= 0 < 1:1.0.5-1 | 1:1.0.5-1 |
| x.org | xdm | >= 0 < 1:1.0.5-1 | 1:1.0.5-1 |
| x.org | xdm | >= 0 < 1:1.0.5-1 | 1:1.0.5-1 |
| x.org | xdm | >= 0 < 1:1.0.5-1 | 1:1.0.5-1 |
| x.org | xf86dga | — | — |
| x.org | xinit | — | — |
| x.org | xload | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3cp9-g7w3-6jqq: X
ghsa_unreviewed·2022-05-01
CVE-2006-4447 [HIGH] GHSA-3cp9-g7w3-6jqq: X
X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.
OSV
CVE-2006-4447: X
osv·2006-08-30·CVSS 7.2
CVE-2006-4447 [HIGH] CVE-2006-4447: X
X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.
Debian
CVE-2006-4447: libx11 - X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xte...
vendor_debian·2006·CVSS 7.2
CVE-2006-4447 [HIGH] CVE-2006-4447: libx11 - X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xte...
X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.
Scope: local
bookworm: resolved (fixed in 2:1.0.0-7)
bullseye: resolved (fixed in 2:1.0.0-7)
forky: resolved (fixed in 2:1.0.0-7)
sid: resolved (fixed in 2:1.0.0-7)
trixie: resolved (fixed in 2:1.0.0-7)
Red Hat
CVE-2006-4447: X
vendor_redhat·CVSS 7.2
CVE-2006-4447 [HIGH] CVE-2006-4447: X
X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.
Statement: Not Vulnerable. This issue does not exist in Red Hat Enterprise Linux 2.1 or 3. This issue not exploitable in Red Hat Enterprise Linux 4. A detailed analysis of this issue can be found in the Red Hat Bug Tracking System:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=195555
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Unchecked Return Value
mitre_cwe
CWE-252 Unchecked Return Value
CWE-252: Unchecked Return Value
The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.
Two common programmer assumptions are "this function call can never fail" and "it doesn't matter if this function call fails". If an attacker can force the function to fail or otherwise return a value that is not expected, then the subsequent program logic could lead to a vulnerability, because the product is not in a state that the programmer assumes. For example, if the program calls a function to drop privileges but does not check the return code to ensure that privileges were successfully dropped, then the program will continue to operate with the higher privileges.
Background: Many functions will return some val
CWE
Improper Check for Unusual or Exceptional Conditions
mitre_cwe
CWE-754 Improper Check for Unusual or Exceptional Conditions
CWE-754: Improper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
The programmer may assume that certain events or conditions will never occur or do not need to be worried about, such as low memory conditions, lack of access to resources due to restrictive permissions, or misbehaving clients or components. However, attackers may intentionally trigger these unusual conditions, thus violating the programmer's assumptions, possibly introducing instability, incorrect behavior, or a vulnerability. Note that this entry is not exclusively about the use of exceptions and exception handling, which are mechanisms for both checking
CWE
Improper Check for Dropped Privileges
mitre_cwe
CWE-273 Improper Check for Dropped Privileges
CWE-273: Improper Check for Dropped Privileges
The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
If the drop fails, the product will continue to run with the raised privileges, which might provide additional access to unprivileged users.
Background: In Windows based environments that have access control, impersonation is used so that access checks can be performed on a client identity by a server with higher privileges. By impersonating the client, the server is restricted to client-level security -- although in different threads it may have much higher privileges.
Modes of Introduction:
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic. This issue is li
http://lists.freedesktop.org/archives/xorg/2006-June/016146.htmlhttp://mail.gnome.org/archives/beast/2006-December/msg00025.htmlhttp://secunia.com/advisories/21650http://secunia.com/advisories/21660http://secunia.com/advisories/21693http://secunia.com/advisories/22332http://secunia.com/advisories/25032http://secunia.com/advisories/25059http://security.gentoo.org/glsa/glsa-200608-25.xmlhttp://security.gentoo.org/glsa/glsa-200704-22.xmlhttp://www.debian.org/security/2006/dsa-1193http://www.kb.cert.org/vuls/id/300368http://www.mandriva.com/security/advisories?name=MDKSA-2006:160http://www.securityfocus.com/bid/19742http://www.securityfocus.com/bid/23697http://www.vupen.com/english/advisories/2006/3409http://www.vupen.com/english/advisories/2007/0409http://lists.freedesktop.org/archives/xorg/2006-June/016146.htmlhttp://mail.gnome.org/archives/beast/2006-December/msg00025.htmlhttp://secunia.com/advisories/21650http://secunia.com/advisories/21660http://secunia.com/advisories/21693http://secunia.com/advisories/22332http://secunia.com/advisories/25032http://secunia.com/advisories/25059http://security.gentoo.org/glsa/glsa-200608-25.xmlhttp://security.gentoo.org/glsa/glsa-200704-22.xmlhttp://www.debian.org/security/2006/dsa-1193http://www.kb.cert.org/vuls/id/300368http://www.mandriva.com/security/advisories?name=MDKSA-2006:160http://www.securityfocus.com/bid/19742http://www.securityfocus.com/bid/23697http://www.vupen.com/english/advisories/2006/3409http://www.vupen.com/english/advisories/2007/0409
2006-08-30
Published