CVE-2006-4447 - CVE House
Back to Database
Status published High CVE-2006-4447

X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans,...

Vulnerability Description

X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-4447

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

emu-linux-x87-xlibs, x11r6, x11r7, xdm, xf86dga, xinit, xload, xorg-server, xterm
Vulnerable Versions:
7.0_r1, 6.7.0, 6.8, 6.8.1, 6.8.2, 1.0, 1.0.1, 1.0.2, 1.0.3, 1.0.0, 1.0.2_r5, 1.02_r5, 214

Timeline

Official Publish: August 30th, 2006
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.