Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2006-2451 | First vendor Publication | 2006-07-07 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 4.6 | Attack Range | Local |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function and a program that causes a core dump file to be created in a directory for which the user does not have permissions. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2451 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-399 | Resource Management Errors |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:11336 | |||
Oval ID: | oval:org.mitre.oval:def:11336 | ||
Title: | The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function and a program that causes a core dump file to be created in a directory for which the user does not have permissions. | ||
Description: | The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function and a program that causes a core dump file to be created in a directory for which the user does not have permissions. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2006-2451 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
ExploitDB Exploits
id | Description |
---|---|
2006-07-18 | Linux Kernel 2.6.13 <= 2.6.17.4 - prctl() Local Root Exploit (logrotate) |
2006-07-13 | Linux Kernel 2.6.13 <= 2.6.17.4 - sys_prctl() Local Root Exploit (3) |
2006-07-11 | Linux Kernel 2.6.13 <= 2.6.17.4 - sys_prctl() Local Root Exploit |
OpenVAS Exploits
Date | Description |
---|---|
2009-10-10 | Name : SLES9: Security update for Linux kernel File : nvt/sles9p5020521.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
27030 | Linux Kernel prctl Core Dumpe Handling Local Privilege Escalation Linux Kernel contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an error occurs during handling of core dumps by the 'prctl' function. This flaw may allow privilege escalation and lead to a loss of Integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2012-05-17 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_kernel-1900.nasl - Type : ACT_GATHER_INFO |
2007-12-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_kernel-1896.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-311-1.nasl - Type : ACT_GATHER_INFO |
2006-07-13 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2006-0574.nasl - Type : ACT_GATHER_INFO |
2006-07-10 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2006-0574.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:20:03 |
|
2024-11-28 12:08:58 |
|
2024-08-02 12:04:31 |
|
2024-08-02 01:01:55 |
|
2024-02-02 01:04:13 |
|
2024-02-01 12:01:56 |
|
2023-11-07 21:48:03 |
|
2023-09-05 12:03:57 |
|
2023-09-05 01:01:47 |
|
2023-09-02 12:04:01 |
|
2023-09-02 01:01:47 |
|
2023-08-12 12:04:46 |
|
2023-08-12 01:01:48 |
|
2023-08-11 12:04:05 |
|
2023-08-11 01:01:50 |
|
2023-08-06 12:03:51 |
|
2023-08-06 01:01:48 |
|
2023-08-04 12:03:56 |
|
2023-08-04 01:01:50 |
|
2023-07-14 12:03:55 |
|
2023-07-14 01:01:49 |
|
2023-03-29 01:04:11 |
|
2023-03-28 12:01:54 |
|
2022-10-11 12:03:29 |
|
2022-10-11 01:01:40 |
|
2021-05-04 12:04:03 |
|
2021-04-22 01:04:37 |
|
2020-05-23 00:17:48 |
|
2018-10-18 21:20:08 |
|
2017-10-11 09:23:41 |
|
2016-06-28 15:47:32 |
|
2016-04-26 14:38:10 |
|
2014-02-17 10:35:55 |
|
2013-05-11 10:57:37 |
|