CVE-2006-0071: Medium severity Gentoo App-crypt Pinentry vulnerability
Published Jan 4, 2006
·Updated
The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.
Affected Software
3 affected components
Gentoo App-crypt Pinentry=0.7.2
Gentoo App-crypt Pinentry=0.7.2-r1
Gentoo Linux
Remediation
Patch Available
Patch Available
Event History
Jan 4, 2006
CVE Published
12:03 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0071?
CVE-2006-0071 is considered a high severity vulnerability due to its potential to allow local users to read or overwrite arbitrary files as gid 0.
2
How do I fix CVE-2006-0071?
To fix CVE-2006-0071, update the pinentry package to version 0.7.2-r2 or later on Gentoo Linux.
3
Who is affected by CVE-2006-0071?
CVE-2006-0071 affects users of Gentoo Linux running pinentry versions before 0.7.2-r2.
4
What type of attack does CVE-2006-0071 enable?
CVE-2006-0071 enables local users to exploit setgid bits to manipulate files and gain elevated access as gid 0.
5
Is CVE-2006-0071 a remote or local vulnerability?
CVE-2006-0071 is a local vulnerability, meaning it can only be exploited by users with local access to the system.