CVE-2006-1174: Low severity Debian shadow vulnerability
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1174?
CVE-2006-1174 is considered a moderate severity vulnerability due to potential unauthorized access to user mailboxes.
How do I fix CVE-2006-1174?
To fix CVE-2006-1174, upgrade the shadow-utils package to version 4.0.8 or later.
What systems are affected by CVE-2006-1174?
CVE-2006-1174 affects shadow-utils versions before 4.0.8, specifically for Debian systems.
What are the potential risks of CVE-2006-1174?
The risks of CVE-2006-1174 include the possibility for attackers to read or modify user mailboxes due to improper permissions.
Is CVE-2006-1174 exploitable?
Yes, CVE-2006-1174 is exploitable, allowing unauthorized access if the software is running a vulnerable version.