The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: debian
Published: 2006-07-05T18:00:00
Updated: 2024-08-07T17:43:28.569Z
Reserved: 2006-05-04T00:00:00
Link: CVE-2006-2194
Vulnrichment
No data.
NVD
Status : Modified
Published: 2006-07-05T18:05:00.000
Modified: 2024-11-21T00:10:46.023
Link: CVE-2006-2194
Redhat
No data.