Vserver Util-Vserver vulnerabilities
3 known vulnerabilities affecting vserver/util-vserver.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2005-4418P4HIGHCVSS 7.5v0v0.30.2092005-12-31
CVE-2005-4418 [HIGH] CVE-2005-4418: util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debia
util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could allow local users to conduct unauthorized activities.
nvd
CVE-2006-1656P4HIGHCVSS 7.2≤ 0.30.210v0.30.2092006-04-06
CVE-2006-1656 [HIGH] CVE-2006-1656: vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is inva
vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root.
nvdosv
CVE-2005-4347P4MEDIUMCVSS 5.0≥ 0, < 0.30.208-12005-12-31
CVE-2005-4347 [MEDIUM] CVE-2005-4347: The Linux 2
The Linux 2.4 kernel patch in kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux does not correctly set the "chroot barrier" with util-vserver, which allows attackers to access files on the host system that are outside of the vserver.
osv