The winbind plugin in pppd for ppp 2.4.4 and earlier...
Vulnerability Description
The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-2194
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:119
- http://www.osvdb.org/26994
- http://www.debian.org/security/2006/dsa-1106
- http://secunia.com/advisories/20963
- http://secunia.com/advisories/20987
- http://secunia.com/advisories/20996
- http://secunia.com/advisories/20967
- http://www.securityfocus.com/bid/18849
- http://www.ubuntu.com/usn/usn-310-1
More from point-to-point protocol project
View All →Affected Vendor
point-to-point protocol project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.