CVE-2006-1656: High severity vserver util-vserver vulnerability
Published Apr 6, 2006
·Updated
vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root.
Affected Software
2 affected components
vserver util-vserver<=0.30.210
vserver util-vserver=0.30.209
Remediation
Patch Available
Patch Available
Event History
Apr 6, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1656?
CVE-2006-1656 is rated as a high severity vulnerability due to its potential for local users to execute root-level commands.
2
How do I fix CVE-2006-1656?
To fix CVE-2006-1656, you should upgrade to util-vserver version 0.30.210 or later.
3
What systems are affected by CVE-2006-1656?
CVE-2006-1656 affects util-vserver version 0.30.209 and versions up to 0.30.210.
4
What type of vulnerability is CVE-2006-1656?
CVE-2006-1656 is a command execution vulnerability that can lead to privilege escalation.
5
Who is impacted by CVE-2006-1656?
Local users on systems utilizing vulnerable versions of util-vserver are impacted by CVE-2006-1656.